CVE-2026-66747
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
- Affected products
- Openwrt, Zbtlink Router Firmware
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-506
- NVD status
- Received
- Published
- 2026-08-05
2 known exploits for CVE-2026-66747
Proof-of-concept code and exploit modules indexed by Sploitus