Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
This past spring, the FCC announced a sweeping ban on new foreign-made routers โ like the kind you use to get online with your ISP and connect all your devices to Wi-Fi. This was all done in the nameโฆ
Affiliate links on Android Authority may earn us a commission. Learn more.
This past spring, the FCC announced a sweeping ban on new foreign-made routers โ like the kind you use to get online with your ISP and connect all your devices to Wi-Fi. This was all done in the name of national security, but just how real of a threat do routers pose? The discovery of a new security vulnerability in some Chinese-made routers may have you looking at the FCCโs action in a slightly more sympathetic light.
Jacob Baines at VulnCheck shares his analysis of routers made by Zbtlink, sold under both that and Wiflyer branding. While neither are huge names in the router space, theyโre still sold through US retailers like Amazon , and have been around for years โ so, plenty of time for these devices to make some inroads on the market.
When we think about routers posing a security risk, there are all sorts of different ways that could happen. That could be anything as explicit as configuring the routers with a secret backdoor login, to just giving them such poorly coded software that itโs trivial to exploit flaws. With these Zbtlink routers, the risk feels far closer to that first option.
While thereโs no hard-coded backdoor account , what the Zbtlink routers are doing might be even worse. VulnCheck discovered that theyโre configured to ping a list of remote servers, including one with a clear reference to Zbtlink in the domain. And then if that remote server ends up answering the ping, the router justโฆ gives it full root access, no authentication needed, whatsoever. Itโs basically like dialing a phone number and then doing whatever the person who answers tells you to do, without ever bothering to establish their identity.
From a security engineering perspective, thatโs what we technically call โcrazy.โ All an attacker has to do is intercept the connection and present themselves as the Zbtlink server, and then they can just sit back and wait for routers to connect, no secret password required.
Thankfully, there are mitigation steps that owners can take, blocking connections to these servers in the first place. But that this is even happening is still incredibly illuminating, and only makes you wonder how many other vulnerabilities exist in network devices out there that havenโt even been (publicly) discovered yet.
How do you know if youโre impacted? Since the branding could vary here, the best way looks like checking your routerโs model number against this list VulnCheck provides:
Read Full Story at Android Authority โ

