Chinese Router Backdoor Leaves Millions of Homes Exposed to Hackers
By 813 Staff
A major product shift is underway — Chinese Router Backdoor Leaves Millions of Homes Exposed to Hackers, according to The Hacker News (@TheHackersNews) (in the last 24 hours).
Source: https://x.com/TheHackersNews/status/2085276294582063347
The expectation was that cheap, off-brand networking gear would carry vulnerabilities—sloppy firmware, unpatched CVEs, maybe a hardcoded admin password or two. What security researchers actually found embedded in a wave of Chinese-made routers was far more deliberate: a fully functional root backdoor, quietly baked into the device’s boot chain, that hands a remote attacker complete control over the hardware the moment it powers on. Internal documents from the research team that broke the story, shared via The Hacker News (@TheHackersNews), describe the implant as sophisticated enough to survive firmware reflashing and standard factory resets.
The backdoor, dubbed “ENDLESSDOORS” by the analysts who reverse-engineered it, was discovered on multiple router models shipped to distributors in Southeast Asia and Eastern Europe over the past eighteen months. Engineers close to the project say the malicious code is not a simple add-on; it is integrated directly into the device’s U-Boot bootloader, meaning it executes before the operating system even loads. That level of access allows an attacker to exfiltrate network traffic, redirect DNS queries, or brick the device remotely, all while remaining invisible to conventional antivirus scans and most intrusion detection systems.
The supply-chain attack appears to target smaller, white-label manufacturers rather than major brands, but the sheer volume of affected units is concerning. The researchers have not yet named the specific factories or distribution partners, and they caution that the provenance of the compromised firmware remains unconfirmed. The rollout of detection tools has been anything but smooth; the team’s initial advisory was delayed by two weeks while they verified that the backdoor was not a false positive from a legitimate debugging interface.
For enterprise IT teams and managed service providers, the implications are immediate. Any router acquired from low-cost overseas vendors should be treated as potentially compromised until the bootloader is verified. The researchers are expected to release a full technical deep-dive and a detection script within the next ten days, but they are already advising organizations to isolate suspect devices immediately. What remains unclear is how deeply the supply chain was penetrated—and whether this was a single rogue operator or a broader, coordinated effort. Until those questions are answered, the safest assumption is that the hardware on your shelf may not be yours alone.
Source: https://x.com/TheHackersNews/status/2085276294582063347

