Zbtlink “backdoor” Cybersecurity Issue a Reminder to Use Secure Routers
I’ve said it before that I don’t trust any routers that I did not create or control myself and I’m especially concerned about any of the Cloud based hardware out there. This is why large portions of the internet around the world have zombie routers of various vendors, used for hacking. Those who value security create their own routers from scratch and at a minimum use OpenSource routing software. Even if it’s not malicious as Zbtlink claims, or any other maker claims whether Cisco or Grandstream, these should all be considered backdoors and I operate under the assumption that most hardware should be considered compromised.
We can see there are worse offenders in the FBI’s list of most compromised routers
D-Link (Taiwan), Zyxel (Taiwan), NETGEAR (USA) and TP-Link (China). Notably, only one company, TP-Link is a Chinese company and this is why I find it concerning how the media and security community reacts without objectivity. Clearly all of those brands and more have huge security issues, whether we are going to call them intentional backdoors, only if a Chinese company is involved, they are unacceptable and if you value security, you cannot use closed-source hardware. Now, in all fairness, these are non-enterprise brands and models, but that’s all the more reason that they should be very secure. The reality is that a lot of firmware update options and remote help options are requested by the ISPs for ease of management, but this Cloud/remote access management option is precisely what makes any remotely accessed router or firewall, so dangerous in my opinion.
https://tech.yahoo.com/cybersecurity/articles/fbi-just-named-18-popular-111700113.html
Zbtlink’s response is included below:

Whether it is malicious as the media says, I would say that Zbtlink has clearly had a lapse of security in their remote access methods, as has been found in everything from Cisco ASA products, to Fortinet etc.., and it will not be the last until companies tighten their policies and rethink if it’s sensible to allow the whole internet to login to critical routers and firewalls.
I will point out one distinction here though, the media is describing these as backdoors and it appears they are only being called such because this is a Chinese vendor. These Zbtlink routers apparently have cloud and remote management capabilities, which hardly sounds different than Grandstream VOIP phones or Cisco Meraki products for example, which I argue will also be exploited at some point.
The real solution is to use opensource routing and firewall tools that don’t have remote/Cloud access features which are either backdoored on purpose or poorly implemented.
My company regular consults on and helps deploy secure routing and firewall solutions, so our clients never have to deal with these issues, and yes we get them to lock down their devices so the public cannot login.
Security Issues with Cloud Network Devices like Cisco Meraki


