B
今週中
中国のZbtlink社製ルーターの少なくとも20モデルのファームウェアに、「ENDLESSDOORS」と呼ばれるバックドアが組み込まれていることがVulnChe…
📌 一言でいうと
中国のZbtlink社製ルーターの少なくとも20モデルのファームウェアに、「ENDLESSDOORS」と呼ばれるバックドアが組み込まれていることがVulnCheck社により発見されました。このバックドアはroot権限でのコマンド実行を可能にし、35秒ごとに外部サーバーと通信します。メーカー側は「サービスメンテナンスツール」であると主張していますが、実態は認証なしでシステムを操作できる危険な機能となっています。
🔍該当判定
- 社内で Zbtlink 製のルーターを利用している
- Zbtlink 製のルーターを拠点間接続やゲストWi-Fi用に使用している
- Zbtlink 製のルーターを外部から管理するためにインターネットに公開している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Zbtlink製ルーターの使用を停止し、信頼性の高い代替製品への移行を検討してください。また、ネットワーク境界での不審な外部通信(C2通信)がないか監視を強化してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Zbtlink製ルーターにおけるバックドア(ENDLESSDOORS)について
お疲れさまです。Zbtlink製ルーターのファームウェアにバックドアが組み込まれている件について情報共有します。
■ 概要
VulnCheck社の調査により、Zbtlink製ルーターの複数モデルに「ENDLESSDOORS」というバックドアがプリインストールされていることが判明しました。この機能により、攻撃者は認証なしでroot権限でのコマンド実行が可能となり、35秒間隔で外部サーバーと通信を行います。メーカーはメンテナンス用ツールと主張していますが、セキュリティ上のリスクは極めて高い状態です。
■ 影響範囲
- Zbtlink製ルーター(少なくとも20モデルのファームウェア)
■ 対応手順
1. 社内および拠点ネットワークにおいてZbtlink製ルーターが使用されていないか資産確認を行ってください。
2. 使用が確認された場合は、速やかにネットワークから切り離し、代替機への交換を検討してください。
3. 該当機器が稼働していた環境では、不審なアウトバウンド通信のログを確認してください。
■ 参考情報
- VulnCheck Analysis / xakep report
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Zbtlink製ルーターのファームウェアにバックドアが組み込まれている件について情報共有します。
■ 概要
VulnCheck社の調査により、Zbtlink製ルーターの複数モデルに「ENDLESSDOORS」というバックドアがプリインストールされていることが判明しました。この機能により、攻撃者は認証なしでroot権限でのコマンド実行が可能となり、35秒間隔で外部サーバーと通信を行います。メーカーはメンテナンス用ツールと主張していますが、セキュリティ上のリスクは極めて高い状態です。
■ 影響範囲
- Zbtlink製ルーター(少なくとも20モデルのファームウェア)
■ 対応手順
1. 社内および拠点ネットワークにおいてZbtlink製ルーターが使用されていないか資産確認を行ってください。
2. 使用が確認された場合は、速やかにネットワークから切り離し、代替機への交換を検討してください。
3. 該当機器が稼働していた環境では、不審なアウトバウンド通信のログを確認してください。
■ 参考情報
- VulnCheck Analysis / xakep report
対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] Backdoor (ENDLESSDOORS) in Zbtlink Routers
Dear IT/Security Team,
We are sharing information regarding a critical security issue found in Zbtlink routers.
■ Overview
VulnCheck has identified a backdoor named 'ENDLESSDOORS' embedded in the firmware of at least 20 Zbtlink router models. This implant allows unauthenticated root access and establishes communication with external C2 servers every 35 seconds. Although the manufacturer claims this is a 'service maintenance tool,' it poses a severe security risk.
■ Scope
- Zbtlink routers (at least 20 models across firmware versions from the last two years).
■ Recommended Actions
1. Audit your network infrastructure to identify any Zbtlink routers in use.
2. If found, immediately isolate the devices from the network and plan for replacement with a secure alternative.
3. Review network logs for suspicious outbound traffic originating from these devices.
■ Reference
- VulnCheck Analysis / xakep report
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a critical security issue found in Zbtlink routers.
■ Overview
VulnCheck has identified a backdoor named 'ENDLESSDOORS' embedded in the firmware of at least 20 Zbtlink router models. This implant allows unauthenticated root access and establishes communication with external C2 servers every 35 seconds. Although the manufacturer claims this is a 'service maintenance tool,' it poses a severe security risk.
■ Scope
- Zbtlink routers (at least 20 models across firmware versions from the last two years).
■ Recommended Actions
1. Audit your network infrastructure to identify any Zbtlink routers in use.
2. If found, immediately isolate the devices from the network and plan for replacement with a secure alternative.
3. Review network logs for suspicious outbound traffic originating from these devices.
■ Reference
- VulnCheck Analysis / xakep report
Priority: High
Deadline: Immediate