A major cybersecurity threat has emerged in the Wi-Fi router market. Researchers have uncovered multiple hidden backdoors in routers manufactured by Zbtlink, a Chinese company that sells devices under various brand names across North America and beyond. The discovery reveals a serious vulnerability that puts home networks and personal data at risk, and shoppers need to understand what this means for their own equipment and purchasing decisions.
Three Separate Backdoors Found in One Manufacturer
Security researchers discovered not just one but three different backdoors embedded in Zbtlink routers. The first, called Endlessdoors, was identified earlier this month. A deeper investigation then uncovered two additional backdoors named SpeakingStone and DarkLantern, primarily affecting other models from the same manufacturer. These aren’t minor coding errors; they appear to be intentional access points that could allow remote attackers to hijack your router without your knowledge or permission.
The investigation began when researchers purchased an $88 Wi-Fi router from Amazon sold under the brand Deep Orange Technology. Upon examination, they discovered it was a rebranded Zbtlink unit containing multiple backdoors. The router’s firmware dated back to 2019, yet still contained the newly discovered security flaws.
How These Backdoors Operate

The SpeakingStone backdoor is particularly concerning. It connects to servers outside your home network, bypassing your firewall’s security measures. The backdoor contains eight different functions, including the ability to steal your internet service provider login credentials and redirect traffic to fraudulent websites through DNS hijacking. In security terms, researchers classify it as a surveillance implant, designed to extract personal information from infected devices.
The DarkLantern backdoor poses an equally serious threat. Unlike SpeakingStone, this backdoor can receive and execute commands from anywhere on the internet. The security research shows it requires no authentication whatsoever, meaning attackers can issue commands to your router without proving their identity. When researchers installed domain name server controls to track which devices were affected, they discovered over 200 instances across 22 different countries, with 103 appearing to be located in the United States.
Scope of the Problem
The scale of this vulnerability is staggering. When researchers set up monitoring for the SpeakingStone backdoor, they found 390 devices attempting to contact command and control servers. Of those, 363 were Zbtlink routers sold to China Mobile, the country’s largest wireless carrier. However, this represents only devices contacting a backup server. The primary control server remains active and operational, suggesting the total number of compromised devices worldwide is substantially larger than currently detected.
Affected router models include the WE1326, WE2426-C, WE357, WE5926, WE826-T2, WG108, and WG3526, among others. The problem extends beyond Zbtlink’s own branding: these routers have been repackaged and sold under different third-party brand names across the United States, Canada, and Australia. This white-label distribution strategy means you could own one of these compromised devices without realizing the manufacturer.
What the Manufacturer Says

When first confronted about the Endlessdoors backdoor, Zbtlink claimed it was merely a technical support tool designed to help troubleshoot customer issues upon request. The company stated it would suspend sales of affected models and remove firmware downloads from its official website. However, no replacement firmware with security patches has been released to date, leaving existing devices vulnerable.
The discovery of additional backdoors suggests the manufacturer’s explanation was incomplete. Security experts believe Endlessdoors was not an isolated incident but part of a broader pattern of intentional security weaknesses built into Zbtlink products.
What You Should Do
If you own a router from any of the affected models, you face a challenging situation. Since no security patches are available, your options are limited. Consider whether your router sits behind a firewall, as that configuration can block DarkLantern attacks. More importantly, research your router’s actual manufacturer before purchasing. Many consumers don’t realize their bargain-priced routers are rebranded Chinese models with unknown security histories.
The broader takeaway extends beyond individual devices. As tracking of router locations has become a widespread concern, this discovery reinforces the importance of verifying your equipment’s origin and security reputation. The United States government has already moved to ban new foreign-made routers, though exemption processes exist. So far, no Chinese manufacturer has received approval to bypass these restrictions.
When shopping for a new router, verify the manufacturer’s reputation, check for regular security updates, and avoid suspiciously cheap options from unfamiliar brands. Your home network’s security depends on it.

Write Your Review
No reviews yet. Be the first to share your experience!