PT-2026-68096 · Openwrt+1 · Openwrt+1

·

CVE-2026-66747

·

Published

2026-08-05

·

Updated

2026-08-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zbtlink router firmware (affected versions not specified)
Description Zbtlink router firmware contains an embedded remote-control implant known as ENDLESSDOORS, which is integrated as an OpenWrt package (librctl.so). The implant runs as root under the process name kworker to mimic kernel threads. It establishes an unauthenticated, cleartext TCP connection to a hardcoded command-and-control server using port 7000 for commands and port 7001 for interactive-shell callbacks. The implant uses the popen() function to execute received strings as root (uid=0), and a specific rctlbash command provides an interactive root shell. Due to the lack of authentication and encryption, any entity capable of intercepting the network path or controlling the C2 address can achieve unauthenticated remote code execution as root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66747

Affected Products

Openwrt
Zbtlink Router Firmware