Description
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
Published: 2026-08-05
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
Title ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
First Time appeared Zbtlink
Zbtlink cpe2801 Firmware
Zbtlink we1026-5g-wd Firmware
Zbtlink we1326 Firmware
Zbtlink we2007 Firmware
Zbtlink we2008-dsim Firmware
Zbtlink we2416 Firmware
Zbtlink we3326 Firmware
Zbtlink we5927 Firmware
Zbtlink we5931 Firmware
Zbtlink we5931ac Firmware
Zbtlink we826-t3-dsim Firmware
Zbtlink wg108 Firmware
Zbtlink wg1602 Firmware
Zbtlink wg1608-dsim Firmware
Zbtlink wg209 Firmware
Zbtlink wg2105 Firmware
Zbtlink wg2107 Firmware
Zbtlink wg259 Firmware
Zbtlink wg3526 Firmware
Zbtlink z8102ax Firmware
Weaknesses CWE-506
CPEs cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zbtlink
Zbtlink cpe2801 Firmware
Zbtlink we1026-5g-wd Firmware
Zbtlink we1326 Firmware
Zbtlink we2007 Firmware
Zbtlink we2008-dsim Firmware
Zbtlink we2416 Firmware
Zbtlink we3326 Firmware
Zbtlink we5927 Firmware
Zbtlink we5931 Firmware
Zbtlink we5931ac Firmware
Zbtlink we826-t3-dsim Firmware
Zbtlink wg108 Firmware
Zbtlink wg1602 Firmware
Zbtlink wg1608-dsim Firmware
Zbtlink wg209 Firmware
Zbtlink wg2105 Firmware
Zbtlink wg2107 Firmware
Zbtlink wg259 Firmware
Zbtlink wg3526 Firmware
Zbtlink z8102ax Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Zbtlink Cpe2801 Firmware We1026-5g-wd Firmware We1326 Firmware We2007 Firmware We2008-dsim Firmware We2416 Firmware We3326 Firmware We5927 Firmware We5931 Firmware We5931ac Firmware We826-t3-dsim Firmware Wg108 Firmware Wg1602 Firmware Wg1608-dsim Firmware Wg209 Firmware Wg2105 Firmware Wg2107 Firmware Wg259 Firmware Wg3526 Firmware Z8102ax Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-05T14:20:12.478Z

Reserved: 2026-07-27T16:27:47.648Z

Link: CVE-2026-66747

cve-icon Vulnrichment

Updated: 2026-08-05T14:20:07.830Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:30:12Z

Weaknesses