Skip to content
Sunday, 9 August 2026 Dubai · GST
UAE, UNFILTERED
Trend Analysis

Check the Router Under Your Desk

The box under the desk is easy to forget because it usually works. That is precisely why router security stories deserve more attention than they get.

Share this story

The box under the desk is easy to forget because it usually works. That is precisely why router security stories deserve more attention than they get.

Cybersecurity researchers at VulnCheck found a remote-access backdoor in more than 20 router models made by China-based Zbtlink and sold under Zbtlink and Wiflyer names. Reuters reported that the software contacted a specific IP address and Chinese-registered domain every 35 seconds. Zbtlink then suspended sales of affected models, removed relevant firmware downloads and said it was developing fixes.

The Robius Action Brief
Caution
Why it matters

A vulnerable router sits between every device on a home or small-office network and the internet, so a remote-access flaw can have a wider blast radius than one compromised laptop.

Who should care

UAE homes, SMEs, installers and IT teams using Zbtlink or Wiflyer routers, especially cellular and small-office models.

Opportunities

The incident is a useful prompt to inventory forgotten network hardware and establish a firmware-update process.

Risks or limitations

Researchers estimated a large global deployment but could not determine the geographic distribution, so Robius cannot claim a specific UAE exposure level.

What happens next

Zbtlink says it is developing and releasing firmware updates while affected model sales and firmware downloads are suspended.

What you can do

Check the router label and admin page today; if it matches affected Zbtlink or Wiflyer hardware, follow current vendor and researcher mitigation guidance.

Who benefits

Users who identify affected hardware early and follow verified vendor or security-research guidance instead of assuming a password change fixes firmware.

Who can participate

Anyone can check the brand, model and firmware of the router they control; managed office networks should involve the IT provider.

What readers should monitor

Watch the vendor security statement, model-specific firmware guidance and independent researcher updates before reconnecting affected equipment.

There is no evidence that the affected routers are concentrated in the UAE, and the researchers could not say where the estimated global installed base sits. So this is a check-your-hardware story, not a UAE panic story.

What Researchers Found

Reuters reported on August 5 that VulnCheck identified a backdoor, which the researchers named Endlessdoors, in more than 20 router models manufactured by Zbtlink. The devices are sold globally under Zbtlink and Wiflyer names.

VulnCheck CTO Jacob Baines estimated that at least 100,000 affected routers were deployed worldwide. He also said it was not possible to determine exactly where those devices were or how many remained active. That geographic uncertainty is important. Robius cannot turn a global estimate into a UAE number.

According to the research described by Reuters, the backdoor communicated with a specific IP address and a Chinese-registered domain every 35 seconds. Whoever controlled or hijacked those endpoints could potentially take control of the router and reach other devices on the same network.

Reuters said it could not determine why the backdoor existed or whether it had ever been abused.

Zbtlink Says It Was a Support Tool

Zbtlink responded on August 6. In its official statement, the company said the remote-management component was intended only for after-sales troubleshooting and configuration when a customer explicitly requested and authorized support. It said the component had never been used for unauthorized access.

The company also said it had immediately suspended sales of affected models, removed the relevant firmware downloads and was developing and releasing firmware updates to resolve the issue.

That response matters for fairness. The existence of remote-support functionality is not automatically proof of malicious intent. The security problem is that researchers found the implementation could create a route for hostile control. Intended purpose and technical risk can both be true at the same time.

Why the Router Matters More Than It Looks

A laptop is one device. A router is the path used by many devices. In a small office that can include laptops, printers, cameras, payment terminals, phones, storage boxes and smart equipment.

That position makes a router a useful place for an attacker to sit. Even when a device behind it has good security, network control can create opportunities to redirect traffic, probe internal services or watch for weak systems.

This is why changing the Wi-Fi password is not a complete answer to a firmware backdoor. A strong password protects one access path. It does not remove code built into the router software.

The same principle appears in the human layer. Our reconstruction of how a scam call gets control of a victim showed that the attacker does not need to break everything. They need one trusted route. Network infrastructure deserves the same thinking.

The UAE Angle Is Inventory, Not Geography

We found no reliable source establishing how many affected Zbtlink or Wiflyer routers are in the UAE. That means the useful UAE action is not to guess exposure from nationality, brand origin or global shipment estimates.

Instead, inventory the hardware you actually have. Look at the label under or behind the router. Record the manufacturer, model and firmware version. If the device came from an installer, telecom reseller, online marketplace or overseas supplier, do not assume the invoice brand is the same as the manufacturer printed on the hardware.

For an SME, add routers, firewalls, access points and cellular gateways to the same asset list as laptops. The UAE’s Information Assurance Regulation is aimed at entities within its scope rather than every household, but its security logic is useful: identify routing equipment, control interfaces and keep network components securely configured.

That is the unglamorous infrastructure behind the tools in our UAE SME technology stack. Cloud apps do not remove the need to know what is carrying the traffic to them.

What to Do If You Have One

First, do not rely on the product photo. Confirm the exact model on the physical device and the firmware shown in the administration interface.

Second, check Zbtlink’s current security and firmware pages. The company says affected firmware downloads were removed while updates are being developed and released. Guidance can change quickly, so use the latest model-specific instruction rather than an old forum post.

Third, if your exact router is identified as affected and the current security guidance says to remove it from the network, treat that seriously. Reuters reported that VulnCheck’s Baines said removal and monitoring were the mitigation while routers remained vulnerable. A future patched firmware may change that advice, which is why the checked date matters.

Fourth, if this is business equipment, involve whoever manages your network. Replacing a router without preserving the correct internet, firewall, VPN or segmentation configuration can create a different outage or security problem.

Finally, review what sits behind the router. Payment systems and finance workflows deserve extra care. The attack route can be technical, while the final loss is still financial, just as we saw in our deepfake payment-scam guide.

Do Not Confuse a VPN With a Router Fix

A VPN can protect traffic between your device and a VPN provider. It does not remove vulnerable firmware from the router carrying that traffic. If the hardware itself is compromised, the right response starts with the hardware and network architecture.

That is why our UAE VPN guide belongs beside this story, not instead of it. Different tools solve different layers of the problem.

If you are not using Zbtlink or Wiflyer hardware, this incident is still worth five minutes. Find out what router you do use, when it last received an update and whether someone in your home or business is responsible for maintaining it.

The Robius Read

The strongest takeaway is not “Chinese router bad” or “100,000 devices hacked.” Neither is supported by the evidence. The researchers estimated at least 100,000 deployments, did not know their geography and Reuters could not determine whether the backdoor had ever been abused.

The useful lesson is simpler. Network equipment can sit untouched for years because nobody thinks of it as a computer. It is a computer, and often a very privileged one.

Check the label under your desk. That is a better response than checking the headline again.

Sources

Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.