Answer in brief
CVE-2026-66747 records a Critical severity (CVSS 9.8) vulnerability in ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant. The current sources do not mark it as known exploited. The current feed maps Zbtlink/CPE2801 Firmware (generic), Zbtlink/WE1026-5G-WD Firmware (generic), Zbtlink/WE1326 Firmware (generic), Zbtlink/WE2007 Firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Zbtlink/CPE2801 Firmware (generic), Zbtlink/WE1026-5G-WD Firmware (generic), Zbtlink/WE1326 Firmware (generic), Zbtlink/WE2007 Firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Zbtlink/CPE2801 Firmwaregeneric | 22.10.09 | Not reported |
| Zbtlink/WE1026-5G-WD Firmwaregeneric | 21.04.07 | Not reported |
| Zbtlink/WE1326 Firmwaregeneric | 22.02.18_1 | Not reported |
| Zbtlink/WE2007 Firmwaregeneric | 23.08.12 | Not reported |
| Zbtlink/WE2008-DSIM Firmwaregeneric | 23.08.11 | Not reported |
| Zbtlink/WE2416 Firmwaregeneric | 21.03.22_1 | Not reported |
| Zbtlink/WE3326 Firmwaregeneric | 20.09.30 | Not reported |
| Zbtlink/WE5927 Firmwaregeneric | 22.08.10 | Not reported |
| Zbtlink/WE5931AC Firmwaregeneric | 22.05.31 | Not reported |
| Zbtlink/WE5931 Firmwaregeneric | 22.05.31 | Not reported |
| Zbtlink/WE826-T3-DSIM Firmwaregeneric | 21.12.21 | Not reported |
| Zbtlink/WG108 Firmwaregeneric | 21.08.06_1 | Not reported |
| Zbtlink/WG1602 Firmwaregeneric | 23.10.11 | Not reported |
| Zbtlink/WG1608-DSIM Firmwaregeneric | 23.03.16 | Not reported |
| Zbtlink/WG209 Firmwaregeneric | 21.07.28 | Not reported |
| Zbtlink/WG2105 Firmwaregeneric | 22.05.30 | Not reported |
| Zbtlink/WG2107 Firmwaregeneric | 22.09.08 | Not reported |
| Zbtlink/WG259 Firmwaregeneric | 21.03.23 | Not reported |
| Zbtlink/WG3526 Firmwaregeneric | 22.11.01 | Not reported |
| Zbtlink/ZBT-Z8102AX-2SIM Firmwaregeneric | 7.6.7.2-25.0814_114432 | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-66747 records a Critical severity (CVSS 9.8) vulnerability in ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant. The current sources do not mark it as known exploited. The current feed maps Zbtlink/CPE2801 Firmware (generic), Zbtlink/WE1026-5G-WD Firmware (generic), Zbtlink/WE1326 Firmware (generic), Zbtlink/WE2007 Firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Zbtlink/CPE2801 Firmware (generic), Zbtlink/WE1026-5G-WD Firmware (generic), Zbtlink/WE1326 Firmware (generic), Zbtlink/WE2007 Firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Zbtlink/CPE2801 Firmwaregeneric | 22.10.09 | Not reported |
| Zbtlink/WE1026-5G-WD Firmwaregeneric | 21.04.07 | Not reported |
| Zbtlink/WE1326 Firmwaregeneric | 22.02.18_1 | Not reported |
| Zbtlink/WE2007 Firmwaregeneric | 23.08.12 | Not reported |
| Zbtlink/WE2008-DSIM Firmwaregeneric | 23.08.11 | Not reported |
| Zbtlink/WE2416 Firmwaregeneric | 21.03.22_1 | Not reported |
| Zbtlink/WE3326 Firmwaregeneric | 20.09.30 | Not reported |
| Zbtlink/WE5927 Firmwaregeneric | 22.08.10 | Not reported |
| Zbtlink/WE5931AC Firmwaregeneric | 22.05.31 | Not reported |
| Zbtlink/WE5931 Firmwaregeneric | 22.05.31 | Not reported |
| Zbtlink/WE826-T3-DSIM Firmwaregeneric | 21.12.21 | Not reported |
| Zbtlink/WG108 Firmwaregeneric | 21.08.06_1 | Not reported |
| Zbtlink/WG1602 Firmwaregeneric | 23.10.11 | Not reported |
| Zbtlink/WG1608-DSIM Firmwaregeneric | 23.03.16 | Not reported |
| Zbtlink/WG209 Firmwaregeneric | 21.07.28 | Not reported |
| Zbtlink/WG2105 Firmwaregeneric | 22.05.30 | Not reported |
| Zbtlink/WG2107 Firmwaregeneric | 22.09.08 | Not reported |
| Zbtlink/WG259 Firmwaregeneric | 21.03.23 | Not reported |
| Zbtlink/WG3526 Firmwaregeneric | 22.11.01 | Not reported |
| Zbtlink/ZBT-Z8102AX-2SIM Firmwaregeneric | 7.6.7.2-25.0814_114432 | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
Quoted source text, attributed separately from HOL analysis.