The box under the desk is easy to forget because it usually works. That is precisely why router security stories deserve more attention than they get.
Cybersecurity researchers at VulnCheck found a remote-access backdoor in more than 20 router models made by China-based Zbtlink and sold under Zbtlink and Wiflyer names. Reuters reported that the software contacted a specific IP address and Chinese-registered domain every 35 seconds. Zbtlink then suspended sales of affected models, removed relevant firmware downloads and said it was developing fixes.
A vulnerable router sits between every device on a home or small-office network and the internet, so a remote-access flaw can have a wider blast radius than one compromised laptop.
UAE homes, SMEs, installers and IT teams using Zbtlink or Wiflyer routers, especially cellular and small-office models.
The incident is a useful prompt to inventory forgotten network hardware and establish a firmware-update process.
Researchers estimated a large global deployment but could not determine the geographic distribution, so Robius cannot claim a specific UAE exposure level.
Zbtlink says it is developing and releasing firmware updates while affected model sales and firmware downloads are suspended.
Check the router label and admin page today; if it matches affected Zbtlink or Wiflyer hardware, follow current vendor and researcher mitigation guidance.
Users who identify affected hardware early and follow verified vendor or security-research guidance instead of assuming a password change fixes firmware.
Anyone can check the brand, model and firmware of the router they control; managed office networks should involve the IT provider.
Watch the vendor security statement, model-specific firmware guidance and independent researcher updates before reconnecting affected equipment.
There is no evidence that the affected routers are concentrated in the UAE, and the researchers could not say where the estimated global installed base sits. So this is a check-your-hardware story, not a UAE panic story.
What Researchers Found
Reuters reported on August 5 that VulnCheck identified a backdoor, which the researchers named Endlessdoors, in more than 20 router models manufactured by Zbtlink. The devices are sold globally under Zbtlink and Wiflyer names.
VulnCheck CTO Jacob Baines estimated that at least 100,000 affected routers were deployed worldwide. He also said it was not possible to determine exactly where those devices were or how many remained active. That geographic uncertainty is important. Robius cannot turn a global estimate into a UAE number.
According to the research described by Reuters, the backdoor communicated with a specific IP address and a Chinese-registered domain every 35 seconds. Whoever controlled or hijacked those endpoints could potentially take control of the router and reach other devices on the same network.
Reuters said it could not determine why the backdoor existed or whether it had ever been abused.
Zbtlink Says It Was a Support Tool
Zbtlink responded on August 6. In its official statement, the company said the remote-management component was intended only for after-sales troubleshooting and configuration when a customer explicitly requested and authorized support. It said the component had never been used for unauthorized access.
The company also said it had immediately suspended sales of affected models, removed the relevant firmware downloads and was developing and releasing firmware updates to resolve the issue.
That response matters for fairness. The existence of remote-support functionality is not automatically proof of malicious intent. The security problem is that researchers found the implementation could create a route for hostile control. Intended purpose and technical risk can both be true at the same time.
Why the Router Matters More Than It Looks
A laptop is one device. A router is the path used by many devices. In a small office that can include laptops, printers, cameras, payment terminals, phones, storage boxes and smart equipment.
That position makes a router a useful place for an attacker to sit. Even when a device behind it has good security, network control can create opportunities to redirect traffic, probe internal services or watch for weak systems.
This is why changing the Wi-Fi password is not a complete answer to a firmware backdoor. A strong password protects one access path. It does not remove code built into the router software.
The same principle appears in the human layer. Our reconstruction of how a scam call gets control of a victim showed that the attacker does not need to break everything. They need one trusted route. Network infrastructure deserves the same thinking.
The UAE Angle Is Inventory, Not Geography
We found no reliable source establishing how many affected Zbtlink or Wiflyer routers are in the UAE. That means the useful UAE action is not to guess exposure from nationality, brand origin or global shipment estimates.
Instead, inventory the hardware you actually have. Look at the label under or behind the router. Record the manufacturer, model and firmware version. If the device came from an installer, telecom reseller, online marketplace or overseas supplier, do not assume the invoice brand is the same as the manufacturer printed on the hardware.
For an SME, add routers, firewalls, access points and cellular gateways to the same asset list as laptops. The UAE’s Information Assurance Regulation is aimed at entities within its scope rather than every household, but its security logic is useful: identify routing equipment, control interfaces and keep network components securely configured.
That is the unglamorous infrastructure behind the tools in our UAE SME technology stack. Cloud apps do not remove the need to know what is carrying the traffic to them.
What to Do If You Have One
First, do not rely on the product photo. Confirm the exact model on the physical device and the firmware shown in the administration interface.
Second, check Zbtlink’s current security and firmware pages. The company says affected firmware downloads were removed while updates are being developed and released. Guidance can change quickly, so use the latest model-specific instruction rather than an old forum post.
Third, if your exact router is identified as affected and the current security guidance says to remove it from the network, treat that seriously. Reuters reported that VulnCheck’s Baines said removal and monitoring were the mitigation while routers remained vulnerable. A future patched firmware may change that advice, which is why the checked date matters.
Fourth, if this is business equipment, involve whoever manages your network. Replacing a router without preserving the correct internet, firewall, VPN or segmentation configuration can create a different outage or security problem.
Finally, review what sits behind the router. Payment systems and finance workflows deserve extra care. The attack route can be technical, while the final loss is still financial, just as we saw in our deepfake payment-scam guide.
Do Not Confuse a VPN With a Router Fix
A VPN can protect traffic between your device and a VPN provider. It does not remove vulnerable firmware from the router carrying that traffic. If the hardware itself is compromised, the right response starts with the hardware and network architecture.
That is why our UAE VPN guide belongs beside this story, not instead of it. Different tools solve different layers of the problem.
If you are not using Zbtlink or Wiflyer hardware, this incident is still worth five minutes. Find out what router you do use, when it last received an update and whether someone in your home or business is responsible for maintaining it.
The Robius Read
The strongest takeaway is not “Chinese router bad” or “100,000 devices hacked.” Neither is supported by the evidence. The researchers estimated at least 100,000 deployments, did not know their geography and Reuters could not determine whether the backdoor had ever been abused.
The useful lesson is simpler. Network equipment can sit untouched for years because nobody thinks of it as a computer. It is a computer, and often a very privileged one.
Check the label under your desk. That is a better response than checking the headline again.
Sources
• Reuters: Researchers identify Zbtlink router backdoor — Reporting on the affected brands, model count, global deployment estimate, communication behavior and unresolved questions.
• Reuters: Zbtlink suspends affected router sales — Follow-up reporting on the company response, suspended sales and mitigation discussion.
• Zbtlink: Official statement — Primary company statement on intended support use, sales suspension, firmware removal and planned updates.
• Zbtlink: Security vulnerabilities and bug fixes — Company security page for firmware and vulnerability notices.
• UAE TDRA: Information Assurance Regulation — UAE security framework used only as a general network-control reference for entities within its scope.
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.



