
Two Preinstalled Backdoors in Chinese ZBT Routers Give Attackers Full Root Control
Security researchers report that some ZBT routers made in China ship with two hidden implants, letting unauthenticated attackers take complete control without any login.
Security researchers have reported that some ZBT routers manufactured in China are being shipped with two separate hidden implants that give unauthenticated attackers full root access to the devices. The finding, published by The Hacker News, underscores a serious supply chain risk: the hardware you plug into your network may already be compromised before you even take it out of the box.
Root access is the highest level of control on a computer or network device. An unauthenticated attacker is someone who can obtain that access without needing a username or password. In everyday terms, this means an outsider can silently take over the router, change its settings, install malicious software, and monitor every piece of data that passes through it. Because a router sits at the boundary between your local network and the internet, a compromised router can undermine the security of every device connected to it.
The two implants are likely hidden in the router's firmware, which is the built-in software that controls how the hardware works. Because the code is part of the factory image, it survives a normal reboot and is not removed by resetting the device to its default settings. An attacker who finds the device over the internet or on a local network can use these backdoors, which are hidden methods of entry that bypass normal security checks, to gain root control without any credentials.
For website owners and businesses, the consequences can be severe. An attacker with root control of a router can redirect web traffic to fake websites, intercept login credentials, or tamper with DNS queries, the internet's phonebook that turns domain names into IP addresses. If a company's office router is compromised, employees may unknowingly send sensitive information to the attacker. Even a home router used for remote work can become a launching point for attacks against a business network.
The presence of two implants in a single device suggests a deliberate, multi-layered backdoor design. Having two separate implants makes the compromise harder to remove, because deleting one may not eliminate the other. This type of preinstalled backdoor is extremely difficult for ordinary users to detect, since the router appears to function normally while the malicious code lies dormant or quietly collects data.
For individual users and small businesses, the first step is to check whether your router is a ZBT device or a rebranded model from an unknown vendor. If so, replace it with a router from a well-known manufacturer that publishes security advisories and regular firmware updates. Change the default administrator password immediately, disable remote administration unless absolutely necessary, and make sure your devices use a trusted DNS provider that can block known malicious sites.
Businesses that cannot inspect every router on their network should consider working with a security-first IT partner like AEU-I, which can audit and harden networking infrastructure to reduce the chance that a hidden backdoor becomes an active breach.
How to Protect Yourself
- If you own a ZBT router or an unknown brand, replace it with a router from a well-known company that regularly releases firmware updates.
- Log in to your router's settings page and change the default administrator password right away.
- Turn off remote administration (the feature that lets you manage your router from outside your home or office) unless you really need it.
- Update your router's firmware as soon as a new version is available, because security fixes are often delivered this way.
- Set your computer and phone to use a trusted DNS service, which acts like a phonebook and can block known harmful websites.
- If you run a business, ask your IT team or hosting provider to check your network equipment for unusual behaviour or hidden backdoors.