Chinese Router Maker Zbtlink Caught With a Second Set of Hidden Backdoors
Cybersecurity researchers have found two additional hidden access points, nicknamed "Darklantern" and "Speakingstone," built into more than a dozen Zbtlink router models. The discovery comes just weeks after the same company was caught shipping a separate backdoor called "Endlessdoors" in over 20 other models. Together, the findings point to a pattern of built-in remote access, not a one-time coding mistake.
.
A Second Wave of Hidden Access Points
Security firm VulnCheck has found two more backdoors built into Zbtlink routers, a brand of networking hardware made in China and sold worldwide. The two new backdoors, named "Darklantern" and "Speakingstone," were found in more than a dozen router models.
Jacob Baines, VulnCheck's chief technology officer, said the goal is to warn people they may be using an affected device without knowing it. Zbtlink routers are often resold under other brand names, so the label on the box does not always reveal the true manufacturer.
What the Backdoors Actually Do
Both backdoors give outsiders an easy way to pull information about the home or business network the router is connected to. Speakingstone goes further: it can also redirect network traffic, meaning data meant for one destination could be secretly routed somewhere else. This kind of manipulation could be used to intercept communications or steer users toward malicious servers without their knowledge.
Baines called Speakingstone a "surveillance implant." To confirm how it works, he registered the unclaimed internet address the infected routers were trying to reach. Data from compromised devices soon began arriving. Most of it came from routers active inside China itself, suggesting the tool was built for domestic monitoring — even though routers with the same capability are sold abroad, including in the United States, under different brand names.
Not the First Warning
Darklantern and Speakingstone are not Zbtlink's first problem. Weeks earlier, VulnCheck disclosed "Endlessdoors," a backdoor present in more than 20 Zbtlink router models. That flaw let anyone who controlled certain internet domains pull data from the router and potentially reach other devices on the same network — all without the owner ever noticing.
After that disclosure, Zbtlink suspended sales of the affected routers and pulled the related firmware (the built-in software that runs a device) from its website. The company said the access method was a legitimate remote-support tool and had never been used for anything malicious.
The Company's Response
Michael Xia, a Zbtlink spokesperson, said the company's remote access and cloud features exist only for authorized after-sales support and pose no security risk. He did not answer direct questions about the surveillance capabilities of Speakingstone, nor did he explain why a legitimate support tool would need to redirect network traffic or beacon to unregistered domains — a point Baines specifically raised as inconsistent with the company's explanation.
Part of a Bigger Picture
The Zbtlink case fits into a broader pattern that has alarmed Western governments and security researchers for years: Chinese-made networking equipment quietly phoning home to servers inside China. U.S. regulators have already moved to restrict imports of foreign-made routers over similar concerns, and lawmakers have pushed back against Chinese hardware makers like Huawei and ZTE for years over fears their equipment could be used for state-directed surveillance or sabotage.
Under the Chinese Communist Party, companies operating in China can be compelled to cooperate with state intelligence and security demands, a legal reality that gives extra weight to findings like this one. Critics argue that as long as that legal structure exists, "after-sales support" explanations for undisclosed remote-access tools deserve heavy skepticism rather than automatic trust.
What Happens Next
Zbtlink has not said whether it will issue fixed firmware for Darklantern and Speakingstone the way it promised to do for Endlessdoors. VulnCheck's advice to consumers and businesses remains the same: check router model numbers against the list of affected devices, avoid relying on brand names alone since Zbtlink hardware is resold under many labels, and replace or isolate any device found to be compromised.
The broader question — how many other "support tools" like this exist inside routers, cameras, and other connected devices sold globally — is likely to keep driving scrutiny of Chinese networking hardware for months to come.
.
Sources
- VulnCheck – "ENDLESSDOORS Is Phoning Home. Pick Up." – https://www.vulncheck.com/blog/zbt-endlessdoors
- Reuters – "Chinese-made Zbtlink routers have backdoor, researchers say" – https://www.reuters.com/world/asia-pacific/chinese-made-zbtlink-routers-have-backdoor-researchers-say-2026-08-05/
- The Hacker News – "Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells" – https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
- The Register – "Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway" – https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
- The Standard (Hong Kong) – "Researchers discover additional backdoors in Chinese-made Zbtlink routers" – https://www.thestandard.com.hk/china/article/341125/Researchers-discover-additional-backdoors-in-Chinese-made-Zbtlink-routers
.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0



Comments (0)