{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wg209-firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CPE2801 Firmware","WE1026-5G-WD Firmware","WE1326 Firmware","WE2007 Firmware","WE2008-DSIM Firmware","WE2416 Firmware","WE3326 Firmware","WE5927 Firmware","WE5931 Firmware","WE5931AC Firmware","WE826-T3-DSIM Firmware","WG108 Firmware","WG1602 Firmware","WG1608-DSIM Firmware","WG209 Firmware","WG2105 Firmware","WG2107 Firmware","WG259 Firmware","WG3526 Firmware","ZBT-Z8102AX-2SIM Firmware"],"_cs_severities":["high"],"_cs_tags":["firmware-vulnerability","implant","router","network-security","informational"],"_cs_type":"advisory","_cs_vendors":["Zbtlink"],"content_html":"\u003cp\u003eResearchers have identified a significant security vulnerability in a wide range of Zbtlink wireless router firmware, collectively referred to as the ENDLESSDOORS threat. Attackers are exploiting this vulnerability to deploy a root-level implant, identified as 'rctl' or 'kworker'. The 'rctl' utility is a remote Linux control tool that provides attackers with persistent, unauthorized administrative access to the underlying operating system of the networking hardware. By establishing a phone-home communication mechanism, the implant enables remote command execution and exfiltration of sensitive network traffic. Given the wide array of affected firmware versions and models, this vulnerability represents a severe risk of long-term network compromise for organizations utilizing Zbtlink hardware. Defenders should review device configurations and monitor for unauthorized binary execution within the router's management interfaces or internal shell.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of the ENDLESSDOORS vulnerability allows for complete system compromise of the affected Zbtlink routers. This grants attackers the ability to intercept internal network traffic, manipulate DNS settings, gain persistent access to private segments of the network, and utilize the devices as part of a botnet. The wide scope of affected legacy and modern firmware versions impacts various small office and industrial networking deployments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all Zbtlink router models listed in this brief and isolate them from public-facing internet segments immediately.\u003c/li\u003e\n\u003cli\u003eAudit all administrative logs on networking equipment for the execution of unexpected binaries, specifically processes labeled 'rctl' or 'kworker'.\u003c/li\u003e\n\u003cli\u003eVerify firmware versions against the manufacturer's security download page and update to the latest provided images.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to router interfaces to known, trusted internal management IP ranges.\u003c/li\u003e\n\u003cli\u003eImplement outbound traffic filtering at the network perimeter to block unauthorized 'phone-home' or C2 traffic originating from infrastructure networking devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T21:23:04Z","date_published":"2026-08-05T21:23:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zbtlink-rctl-implant/","summary":"Multiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.","title":"ENDLESSDOORS Vulnerability Affecting Zbtlink Routers","url":"https://feed.craftedsignal.io/briefs/2026-08-zbtlink-rctl-implant/"}],"language":"en","title":"CraftedSignal Threat Feed - WG209 Firmware","version":"https://jsonfeed.org/version/1.1"}