๐Ÿ” CVE Alert

CVE-2026-66747

CRITICAL 9.8

ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.

CWE CWE-506
Vendor zbtlink
Product cpe2801 firmware
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for zbtlink cpe2801 firmware

Be the first to know when new critical vulnerabilities affecting zbtlink cpe2801 firmware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Zbtlink / CPE2801 Firmware
22.10.09
Zbtlink / WE1026-5G-WD Firmware
21.04.07
Zbtlink / WE1326 Firmware
22.02.18_1
Zbtlink / WE2007 Firmware
23.08.12
Zbtlink / WE2008-DSIM Firmware
23.08.11
Zbtlink / WE2416 Firmware
21.03.22_1
Zbtlink / WE3326 Firmware
20.09.30
Zbtlink / WE5927 Firmware
22.08.10
Zbtlink / WE5931 Firmware
22.05.31
Zbtlink / WE5931AC Firmware
22.05.31
Zbtlink / WE826-T3-DSIM Firmware
21.12.21
Zbtlink / WG108 Firmware
21.08.06_1
Zbtlink / WG209 Firmware
21.07.28
Zbtlink / WG259 Firmware
21.03.23
Zbtlink / WG1602 Firmware
23.10.11
Zbtlink / WG1608-DSIM Firmware
23.03.16
Zbtlink / WG2105 Firmware
22.05.30
Zbtlink / WG2107 Firmware
22.09.08
Zbtlink / WG3526 Firmware
22.11.01
Zbtlink / ZBT-Z8102AX-2SIM Firmware
7.6.7.2-25.0814_114432

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vulncheck.com: https://www.vulncheck.com/blog/zbt-endlessdoors zbtlink.com: https://www.zbtlink.com/pages/zbt-router-firmware-download github.com: https://github.com/ycsunjane/rctl vulncheck.com: https://www.vulncheck.com/advisories/zbt-endlessdoors

Credits

Jacob Baines of VulnCheck