{"id":"CVE-2026-66747","published":"2026-08-05T11:16:25.510","lastModified":"2026-08-05T15:17:04.690","description":"Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-506"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ycsunjane/rctl","tags":[]},{"url":"https://www.vulncheck.com/advisories/zbt-endlessdoors","tags":[]},{"url":"https://www.vulncheck.com/blog/zbt-endlessdoors","tags":[]},{"url":"https://www.zbtlink.com/pages/zbt-router-firmware-download","tags":[]}],"exploitRefs":[{"url":"https://github.com/ycsunjane/rctl","tags":[]}],"hasPoc":true,"ai":{"summary":"The Zbtlink router firmware contains an embedded implant called ENDLESSDOORS that provides unauthenticated remote code execution as root, posing a critical security risk.","exploitability":"Exploitation is relatively straightforward due to the unauthenticated and cleartext nature of the command channel, requiring only network access to the C2 server.","blast_radius":"If exploited, this flaw could result in complete control over the router and potentially the entire network, leading to widespread damage or data exfiltration.","remediation":"Disable the ENDLESSDOORS feature in the router firmware or apply the latest patch if available, which is not specified in the description.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","cleartext","root","implant"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:00:51.086Z"}}