CRITICAL
Zbtlink
CVE published 2026-08-05
CVE-2026-66747
The Zbtlink router firmware contains an embedded remote-control implant called ENDLESSDOORS, which is based on the open-source ycsunjane/rctl tool. This implant allows for unauthenticated remote code execution as root, as it communicates with a hardcoded command-and-control server over cleartext TCP without authentication or transport encryption. The CVE record was published on 2026-08-05T11:16:25.510Z an [truncated]