Home / Technology Today / Cybersecurity / Zbtlink Router Backdoor Fou...

visionaries Network Team

08 August, 2026

cybersecurity

A new report says a Zbtlink router backdoor was found in multiple router models, raising concerns about a growing Chinese router security risk for businesses worldwide

A newly disclosed Zbtlink router backdoor has raised cybersecurity concerns after researchers found that multiple router models manufactured by Chinese networking company Zbtlink contain firmware capable of communicating with cloud servers in China. The findings come from cybersecurity firm VulnCheck, which examined 20 router models and reported that every device tested included the same hidden functionality.

According to VulnCheck, the routers automatically connect to external servers approximately every 35 seconds, potentially allowing remote access to the devices and other systems connected to the network. CTO Jacob Baines said the feature could enable a third party to take control of affected routers without requiring users to expose them directly to the internet. More details are available in VulnCheck's technical report: VulnCheck report.

Security Experts Raise Concerns

Researchers estimate that around 100,000 Zbtlink routers may be deployed worldwide, primarily in commercial environments. They also warned that some devices may be sold under different brand names, making it difficult for organizations to identify affected hardware. The discovery highlights a broader Chinese router security risk, particularly for businesses relying on low-cost networking equipment.

Zbtlink, through its parent company Shenzhen Zhibotong Electronics, told CNET that the feature was designed solely for remote after-sales support and not for monitoring user traffic. The company said it may release updated firmware to disable the function. However, VulnCheck reported that every firmware version available on the company's website contained the same remote maintenance feature. Zbtlink's response was reported by CNET.

Businesses Advised to Review Network Devices

Cybersecurity experts recommend that organizations using Zbtlink or rebranded networking equipment review firmware versions, monitor unusual outbound connections, and apply security updates as they become available. Businesses should also audit supply chains to ensure networking hardware comes from trusted vendors.

FAQs

1. What is the Zbtlink router backdoor?
It is a hidden firmware feature identified by VulnCheck that automatically communicates with cloud servers and could allow remote access to affected routers.

2. How many devices are affected?
Researchers examined 20 router models and estimate that around 100,000 devices may be in use globally, though the actual number could be higher.

3. Are home users affected?
Most affected routers are believed to be used in commercial networks, but some consumer devices may also be impacted.

4. What has Zbtlink said about the issue?
The company says the feature was intended for after-sales support and not for surveillance, and it may release firmware updates to remove it.

5. What should router owners do?
Users should check for firmware updates, monitor network traffic, and consider replacing devices if security concerns remain.