You probably didn’t check your router’s firmware for root-level backdoors when you unboxed it. Most people don’t. But for over 100,000 households, that oversight is now a permanent liability. We aren’t talking about a clever exploit discovered by a bored teenager in a basement. We are talking about CVE-2026-66747, a factory-shipped implant dubbed ENDLESSDOORS that comes pre-installed on more than 20 Zbtlink and Wiflyer router models. These devices, sold at major retailers like Amazon, Walmart, and eBay, didn’t get hacked; they were built to be compromised from the start.
As VulnCheck CTO Jacob Baines wrote, these devices weren’t compromised because they were hacked, but because they were shipped that way. The implant, which runs as root and initiates at boot via an init.d script called ‘skworker’, is remarkably chatty. It phones home to hardcoded command-and-control endpoints every 35 seconds, completely unencrypted and without a shred of authentication. Using the reserved string ‘rctlbash’, an operator can gain a live, interactive root shell on your network gateway. Zbtlink, a subsidiary of Shenzhen Zhibotong Electronics, has claimed this is merely an ‘after-sales technical support tool,’ though they have since halted sales and are scrambling to develop a firmware update. Given the nature of the implant, calling it a ‘tool’ is a generous interpretation of a critical, CVSS 9.3-rated security failure.
This isn’t a software bug you can patch away. It is a fundamental breach of the infrastructure layer. When your router is compromised, the entire concept of a secure smart home evaporates. Every AI agent, smart lock, and camera behind that gateway inherits the compromise. If your router is the front door to your digital life, ENDLESSDOORS is a skeleton key handed to a third party before you even plugged the device into the wall. This is a different beast entirely from the iRobot FCC ban. While that case focused on device-level ownership and data authorization, this is an infrastructure-level betrayal that happens before a single smart device even connects to the network.
The smart home industry is already navigating a significant trust deficit, with 71% of Americans already convinced that AI will make their personal data less secure. When the hardware foundation itself is untrustworthy, that skepticism becomes entirely rational. Developers pushing for local-first AI, like the team behind Home Assistant 2026.8, are trying to build a future where your data stays in your house. But that vision assumes the network is neutral ground. ENDLESSDOORS proves that the network is not neutral; it is a hostile environment where the hardware you bought might be working against you.
For the average consumer, the recourse is effectively zero. There is no simple patch, no easy refund, and no way to detect the activity without sophisticated network-level monitoring. You are left with a piece of hardware that is fundamentally broken, sold by a company that viewed your privacy as an optional feature. The financial cost isn’t just the price of the router; it is the cost of replacing every device that might have been exposed while the router was active.
The smart home trust model has always relied on the assumption that the gateway is a secure, private boundary. ENDLESSDOORS shatters that assumption. It forces us to confront the reality that in a globalized supply chain, the most dangerous vulnerability isn’t the one you download — it’s the one that comes in the box. Until we can verify the integrity of our infrastructure, the promise of a secure, AI-driven home remains a fragile, and perhaps dangerous, illusion.
