Video
An investigation has revealed that approximately 100,000 Chinese-made wireless routers installed worldwide contain a feature that allows for remote external control.
It was found that these routers automatically communicate with a specific domain in China roughly every 35 seconds and can execute externally downloaded commands with administrator privileges.
According to the Nihon Shimbun, U.S. cybersecurity firm VulnCheck analyzed 21 types of firmware for wireless routers manufactured by Chinese telecommunications equipment maker Shenzhen Zbtlink and discovered remote management capabilities in all of them.
VulnCheck named this architecture "Endless Doors."
The setup automatically activates the remote management function once the router is powered on, connecting to a specific IP address and a Chinese domain every 35 seconds or so.
In particular, the investigation showed that because there is no authentication process for the communicating party, commands sent from external servers can be executed directly with administrator privileges.
Experts point out that if an attacker takes control of the server, they could remotely hijack the router and compromise other connected devices on the same network, such as computers and smartphones.
VulnCheck estimates that at least 100,000 such routers are installed globally.
The problematic routers were sold under the "Zbtlink" and "Wiflyer" brands, and concerns have been raised that the same feature may also be included in OEM products sold under other brands.
VulnCheck concluded that this issue is not a typical software bug, but rather a feature intentionally embedded at the manufacturing stage.
Stating that the issue cannot be resolved simply by installing modified software and that it is a matter of device reliability itself, the firm recommended disconnecting the affected routers from the network and checking for signs of compromise.
Following the disclosure of the investigation results, the manufacturer suspended sales of the products and removed the relevant firmware from its website.
However, the company explained that the controversial remote management function was an after-sales service feature intended to support device troubleshooting and configurations upon customer request and approval.
It also stated that the feature has never been used for illegal access and that it is providing firmware updates to resolve the issue.
To date, no evidence has been made public that this feature has been exploited in actual cyberattacks or that the Chinese government or other entities were involved.
Reported by Kim Minjeong | Video by Ryu Ji-su | Graphics by Lee Sumin | Produced by SBS Digital News