ChineseMade Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
News Source : Internet
News Summary
- Researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models.
- The implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years.
- The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control infrastructure as often as every 35 seconds.
- An attacker can take advantage of this loophole to obtain a live root shell, and take over control of the router without having to be reachable from the internet.
Cybersecurity researchers have disclosed details of a factoryshipped backdoor implanted in at least 20 Chinese router models from Zbtlink.
Never miss a story from us, subscribe to our newsletter