{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-66747","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-07-27T16:27:47.648Z","datePublished":"2026-08-05T10:50:45.576Z","dateUpdated":"2026-08-05T14:20:12.478Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-08-05T10:55:20.206Z"},"title":"ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant","datePublic":"2026-08-05T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-506","description":"CWE-506 Embedded Malicious Code","type":"CWE"}]}],"affected":[{"vendor":"Zbtlink","product":"CPE2801 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.10.09","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE1026-5G-WD Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.04.07","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE1326 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.02.18_1","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE2007 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"23.08.12","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE2008-DSIM Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"23.08.11","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE2416 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.03.22_1","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE3326 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"20.09.30","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE5927 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.08.10","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE5931 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.05.31","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE5931AC Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.05.31","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WE826-T3-DSIM Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.12.21","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG108 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.08.06_1","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG209 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.07.28","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG259 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"21.03.23","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG1602 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"23.10.11","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG1608-DSIM Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"23.03.16","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG2105 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.05.30","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG2107 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.09.08","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"WG3526 Firmware","platforms":["MIPS","ARM"],"versions":[{"status":"affected","version":"22.11.01","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*"]},{"vendor":"Zbtlink","product":"ZBT-Z8102AX-2SIM Firmware","platforms":["ARM"],"versions":[{"status":"affected","version":"7.6.7.2-25.0814_114432","versionType":"custom"}],"defaultStatus":"unaffected","cpes":["cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.</p>"}]}],"references":[{"url":"https://www.vulncheck.com/blog/zbt-endlessdoors","name":"VulnCheck Research Blog","tags":["technical-description","exploit"]},{"url":"https://www.zbtlink.com/pages/zbt-router-firmware-download","name":"Vendor Firmware Download Page","tags":["product"]},{"url":"https://github.com/ycsunjane/rctl","name":"Upstream Open Source rctl"},{"url":"https://www.vulncheck.com/advisories/zbt-endlessdoors","name":"VulnCheck Advisory","tags":["third-party-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"credits":[{"lang":"en","value":"Jacob Baines of VulnCheck","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"vulncheck"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-05T14:19:25.533200Z","id":"CVE-2026-66747","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-05T14:20:12.478Z"}}]}}