Routers are hardware that connect your home devices to the internet, but a new report find that some models have been shipped with an alarming backdoor — meaning you’re not the only one with access to your devices.
According to a recent post by cybersecurity firm VulnCheck, multiple models of routers manufactured and sold by Zbtlink are compromised, claims the company has since denied.
Jacob Baines, the chief technology officer at VulnCheck who found the
backdoor, said that 20 models made by Zbtlink have been shipped with an implant that communicates with cloud servers in China and could allow an attacker to take over the router and use it to access other connected devices on the router’s network.
Baines said he is concerned that “consumers in the United States are unaware that they are buying these, putting them in their network, and immediately just allowing someone else that they don’t know in a foreign country complete access to their network.”
Baines said he estimates that at least 100,000 routers by Zbtlink have been distributed worldwide, but it’s unclear how many are currently in the United States.
In its post, VulnCheck said Zbtlink routers are sold under that brand name, but also as ZBT, ZBTWiFi and Wiflyer, and you can buy them through large retailers like Amazon, Alibaba or Shopify. The firmware –– or programs that run on your router –– up for download on the company’s page can be hijacked through this backdoor, according to the post.
To understand why this kind of report is so serious, know that a router doesn’t just connect you to the internet –– it’s also a first line of defense against cyberattacks.
A router has a “shield that protects you from attackers, and this implant basically just bypasses that shield and removes a whole bunch of protections that consumers don’t know that they have,” Baines said. Typically, “no one on the internet can talk to your internal network, but that goes away when an attacker is able to compromise the router. They both bypass that firewall that blocks inbound internet connections, and it bypasses network address translation, which allows their internet connection to talk to your internal network.”
Once someone can access your router, they can find out a lot about your most sensitive information. Baines said a compromised router could “definitely track how you’re interacting with the internet, just because it will be able to monitor all your internet traffic.”
Kevin Tackett, CEO of security consulting company Secure Ideas, said this kind of backdoor shows that the vendor is “untrustworthy,” because it means somebody can connect to your wireless router and make changes, or monitor all the traffic that you send through it. If you use Wi-Fi to make calls, “All of your phone calls go through this router. Potentially the attacker could listen in on your phone calls,” he said.

Getty/HuffPost
Zbtlink did not respond to a HuffPost request for comment about the allegations. On its downloads page, the company has a statement denying VulnCheck’s allegations.
“The remote management component mentioned in the report serves solely as an after-sales technical support tool,” the statement reads. “It is intended to assist customers with device troubleshooting and configuration only upon their explicit request and authorization. … Sales of the affected models have been immediately suspended. Downloads for the relevant firmware have been removed from the official website.”
This report follows other allegations about authentication backdoors built in Chinese-made Wi-Fi routers. Last month, the CERT Coordination Center, a U.S. government-backed cybersecurity group, reported a hidden firmware backdoor on several Tenda routers that allow full administrative access to the router that has no known patch. One of the CERT Coordination Center’s recommendations is to disable affected routers.
That kind of advice is in line with what security researchers are recommending for the Zbtlink routers you may have: Get rid of them and replace them ASAP. To do this, look up your router’s model and see if it is named Zbtlink, ZBT, ZBTWiFi or Wiflyer. “They tend to be on the bottom or on the back [of the router] as a label that has a whole bunch of different numbers,” Tackett said.
“It’s possible you’re running it without realizing it, because it goes under multiple different brand names,” Tackett said. “Just do a quick check right now, especially if you got it from maybe Amazon or a wholesale retailer where you’re not quite sure” where your router is from.
And going forward, Baines said it’s better for consumers to stick with well-established brands like Netgear, Ubiquiti and Cisco that are “not going to drop an implant into any of their firmware.”
