🟠 High  |  Source: The Register — Security


Chinese router manufacturer Zbtlink has denied that its firmware contains deliberate backdoors, describing a suspicious remote access function as a legitimate maintenance feature. Despite the denial, the company has paused firmware downloads whilst it addresses the identified security issues. The incident raises serious concerns about the trustworthiness of networking hardware from certain vendors, particularly where undisclosed remote access capabilities are present.

Security Architect’s Take: Audit your environment for any Zbtlink (ZBT) routers, particularly those used in network edge or branch connectivity roles, and consider replacing or air-gapping them until verified clean firmware is available from a trusted source. More broadly, enforce a hardware vendor vetting policy that requires third-party firmware audits before deployment of any networking equipment in sensitive or cloud-connected environments.

Original advisory: Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway