Topic overview
In brief
- VulnCheck discovered a backdoor implant in routers made by Zbtlink that connects to servers in China.
- The implant allows unauthorized access to devices on the router's network, raising cybersecurity concerns.
- This finding has led to legal actions and regulatory measures against foreign-made routers, particularly those from China.
Summary
In a recent report, cybersecurity firm VulnCheck revealed alarming findings regarding routers manufactured by the Chinese company Zbtlink. The investigation focused on 20 different models, all of which were found to contain a backdoor implant embedded in their firmware. This implant allows the routers to automatically connect to cloud servers located in China, potentially granting the company unauthorized access to devices connected to the router's network. Jacob Baines, the chief technology officer at VulnCheck, emphasized the severity of the situation, stating that once a router is plugged into a network, it attempts to reach out to a server in China that can exert full control over the device. This discovery has reignited concerns among cybersecurity experts and lawmakers about the trustworthiness of Chinese-made routers, a sentiment that has been growing for years. The implications of such backdoors are significant, as they could facilitate cyberattacks and data breaches, leading to potential national security threats. In response to these concerns, the state of Texas has taken legal action against TP-Link, another router manufacturer with Chinese origins, alleging that its devices have been used by the Chinese government to conduct cyberattacks in the United States. Furthermore, the Federal Communications Commission (FCC) has implemented a ban on the sale of new foreign-made routers, although exemptions have been granted to certain non-Chinese manufacturers. Notably, this backdoor implant in Zbtlink routers is unprecedented, as no similar vulnerabilities have been reported in TP-Link's products. Baines pointed out that the nature of this implant is particularly concerning because it operates independently, without requiring exposure to the internet. The routers in question are primarily utilized in business environments rather than residential settings, and Baines estimates that around 100,000 of these devices are currently deployed worldwide. However, he cautioned that the actual number of affected devices could be much higher, as many Chinese routers are often white-labeled or rebranded to appear as if they originate from other countries. This practice complicates the identification of potentially compromised devices, as they may be marketed under different brands while still utilizing the same vulnerable firmware. The lack of immediate response from Zbtlink regarding these findings raises further questions about the company's accountability and transparency in addressing cybersecurity risks associated with its products.
