Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor

Aug 6, 2026 — 3:29 PM ET

  • A new report details a massive security flaw in Zbtlink-made routers.
  • The routers are programmed to ping a hard-coded list of servers, traced back to China.
  • Once connected, the routers grant full root access — no authentication required.

This past spring, the FCC announced a sweeping ban on new foreign-made routers — like the kind you use to get online with your ISP and connect all your devices to Wi-Fi. This was all done in the name of national security, but just how real of a threat do routers pose? The discovery of a new security vulnerability in some Chinese-made routers may have you looking at the FCC’s action in a slightly more sympathetic light.

Jacob Baines at VulnCheck shares his analysis of routers made by Zbtlink, sold under both that and Wiflyer branding. While neither are huge names in the router space, they’re still sold through US retailers like Amazon, and have been around for years — so, plenty of time for these devices to make some inroads on the market.

When we think about routers posing a security risk, there are all sorts of different ways that could happen. That could be anything as explicit as configuring the routers with a secret backdoor login, to just giving them such poorly coded software that it’s trivial to exploit flaws. With these Zbtlink routers, the risk feels far closer to that first option.

While there’s no hard-coded backdoor account, what the Zbtlink routers are doing might be even worse. VulnCheck discovered that they’re configured to ping a list of remote servers, including one with a clear reference to Zbtlink in the domain. And then if that remote server ends up answering the ping, the router just… gives it full root access, no authentication needed, whatsoever. It’s basically like dialing a phone number and then doing whatever the person who answers tells you to do, without ever bothering to establish their identity.

From a security engineering perspective, that’s what we technically call “crazy.” All an attacker has to do is intercept the connection and present themselves as the Zbtlink server, and then they can just sit back and wait for routers to connect, no secret password required.

Thankfully, there are mitigation steps that owners can take, blocking connections to these servers in the first place. But that this is even happening is still incredibly illuminating, and only makes you wonder how many other vulnerabilities exist in network devices out there that haven’t even been (publicly) discovered yet.

How do you know if you’re impacted? Since the branding could vary here, the best way looks like checking your router’s model number against this list VulnCheck provides:

CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, Z8102AX-2DSIM

Even though cases like this might seem to support the FCC’s action, a closer look really only highlights the ineffectualness of the ban: The FCC is only targeting new routers, while all these super-insecure old Zbtlink models can continue to be sold. Of course, enacting a sweeping new ban is a hell of a lot easier on an agency than actually doing the legwork to certify the security of existing devices.