{"id":"CVE-2026-66747","published":"2026-08-05T11:16:25.510","lastModified":"2026-08-05T15:17:04.690","description":"Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-506"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ycsunjane/rctl","tags":[]},{"url":"https://www.vulncheck.com/advisories/zbt-endlessdoors","tags":[]},{"url":"https://www.vulncheck.com/blog/zbt-endlessdoors","tags":[]},{"url":"https://www.zbtlink.com/pages/zbt-router-firmware-download","tags":[]}],"exploitRefs":[{"url":"https://github.com/ycsunjane/rctl","tags":[]}],"hasPoc":true,"ai":{"summary":"The Zbtlink router firmware includes an embedded implant called ENDLESSDOORS that provides unauthenticated remote code execution as root over cleartext TCP to a hardcoded C2 server.","exploitability":"Exploitation is relatively straightforward due to the lack of authentication and encryption, requiring only network access to the C2 address or control of the network path.","blast_radius":"If exploited, this flaw could lead to complete compromise of affected routers, allowing unauthorized parties to gain root access and potentially control the entire network infrastructure.","remediation":"Update Zbtlink router firmware to a patched version or replace the affected devices with ones from a trusted vendor.","tags":["rce","auth-bypass","unencrypted","c2","firmware"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:43:08.557Z"}}