Impact
The firmware contains the ENDLESSDOORS remote control implant. Upon boot it runs as root under the kworker process, never opens a listening port but periodically initiates an unauthenticated, unencrypted TCP connection to a hard‑coded C2 server on ports 7000 (command channel) and 7001 (interactive shell). The implant accepts arbitrary commands and forwards them to popen() with root privileges; a special rctlbash command gives an interactive root shell. Because the channel is unauthenticated, any entity that can reach the C2 address, hijack DNS or routing, or know the fallback domain can issue commands and gain full root access on the device.
Affected Systems
Zbtlink firmware for the following models: CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and ZBT-Z8102AX-2SIM. The vulnerability is present in all published builds of these firmwares.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is unavailable but the lack of authentication and encryption means exploitation probability is intrinsically high; an attacker controlling the network path or the C2 domain can trigger arbitrary code execution as root. The vulnerability is not yet listed in the CISA KEV catalogue, but the impact and exposure warrant immediate attention. Likely attack vectors include spoofing the hard‑coded C2 hostname, hijacking DNS, or compromising router connectivity to force traffic to the implant.
OpenCVE Enrichment