These Routers Shipped With Backdoor And Amazon Sold Them For Years
Watch on YouTubeVideo summary
On August 5th, 2026, security researchers from Volc published a critical report revealing that numerous routers sold on Amazon contained built-in backdoors designed to actively contact command and control servers on the internet. Although these specific devices were removed from sale by August 7th of the same year, leaving only "currently unavailable" listings behind, the issue extends far beyond just those models. The affected hardware often uses deceptive naming conventions that mimic reputable brands like TP-Link or WaveLink to confuse consumers; for instance, a device branded as ZBT Link was found attempting unauthorized connections despite being placed on an isolated network. This practice is not new, with evidence suggesting such vulnerabilities have existed since at least 2015, relying on the fact that few people scrutinize inexpensive networking equipment until a dedicated security researcher brings it to light.
The implications of these findings are severe because many users assume they can avoid backdoors by sticking only to well-known brands like Netgear or TP-Link, yet research indicates that even major manufacturers have faced similar issues in their own products. While the video highlights specific problematic models and namesakes created through wordplay, it emphasizes that an exhaustive list of unsafe devices is impossible to compile due to companies frequently rebranding hardware with existing vulnerabilities under new labels. Consequently, relying solely on brand recognition offers no guarantee of security, as there are likely many other routers circulating in the market with identical hidden flaws that remain undetected until a specific investigation exposes them.
For consumers seeking safer alternatives, the video suggests moving away from cheap off-brand devices and considering enterprise-grade solutions or open-source options tailored for home use. Recommended choices include hardware preloaded with OpenSense or pfSense from Netgate, as well as products from Ubiquiti (UniFi), which are praised for their build quality despite some past bugs in specific TP-Link units that lack a bug bounty program and have poor security track records. Tech-savvy users who prefer to customize their own firmware can also look into OpenWRT, an open-source project based on Linux that serves as a robust alternative for building secure routers without relying on proprietary backdoors baked directly into the hardware's operating system.
Ultimately, the most critical takeaway is that once these malicious features are embedded in router firmware, there is often no patch or update available to remove them, meaning affected devices must be physically disconnected from any network immediately. The video urges viewers not only to check their own equipment but also to ensure family members do not use routers with known vulnerabilities, as the risk of data theft and unauthorized remote access remains constant without a fix. While Amazon has temporarily stopped selling these specific models, there is no guarantee that similar devices will disappear entirely from online stores or other retailers in the future, making vigilance and informed purchasing decisions essential for maintaining home network security.
Read the full video transcript
On August 5th of 2026, researchers over
at Volcublished a list of routers that
had built-in back doors being sold on
Amazon. Now, good news is it's August
7th of 2026 and they stopped selling
them. But that's not the complete story.
So, let's look a little bit closer at
exactly what they found and how many
more problems are probably out there.
The title of the blog post is Endless
Doors is Phoning Home Pickup. On my desk
in suburban Philadelphia, an AX 3000
dual SIM 5G CPE Wi-Fi 6 plugged into an
isolated research network. Its status
lights blink and twinkle continuously
and attempts to reach command and
control servers on the internet. So even
if you have this behind another
firewall, it's reaching out. This isn't
like an open port that someone can log
into. This device actively reaches out.
And the research goes on from there to
list out that they are sold under the
name ZBT link and why Flyier. I kind of
like Flyier. I think it's a cool name.
Uh they're sold on stores like ZBTI.com
and ZBTLink.com.
And if you notice the naming here,
AX3000.
This is really similar to TPLink's name.
So calling it a ZBT link, I think
there's a little bit of play on words
going. I went to the Amazon store and
when I first seen this, I went right to
the Amazon store and noticed it was for
sale. It's not for sale anymore. They're
still listed. They haven't taken down
the store. But if you try to purchase
any of these models, they all say
currently unavailable. They were
available as of just the other day. But
I just find it really interesting that
they have called this the AC1200. Where
have I seen that name before? There's a
Wavelink AC1200 and probably I think
there's some TPLink models that have
some similar names. This is part of the
problem as well is I'm willing to bet
there's lots of other router brands with
also very similar names that have the
same back door. This has actually been
here for years. This isn't anything new.
This appears to date all the way back to
2015. The reality of a lot of these
inexpensive routers is there's just not
a lot of people looking at them. Which
is why when someone takes the time to
look at it and it's a proper security
researcher and they have a place to post
a blog to get attention that convergence
of things is the only way we know about
this. And I know some of you are
thinking, well, I don't buy these weird
off-brand play on word different routers
that I find on Amazon. I stick with
brands I know like Netgear Nighthawk.
But Wendell did a video back in May of
2026 and a right up here in his forums
that I'll leave a link to talking about
the back door he found in the Nekar
Nighthawk. I believe he also did a video
in Gamers Nexus channel about the same
topic. And I do want to give a shout out
to the low-level channel who also covers
this as a topic and found several back
doors in different router models and has
an entire great breakdown of how to deep
dive into these and find these backd
doors. Now, there's no reasonable way to
make an exhaustive list of everything
you shouldn't buy. I just highlighted a
couple models that I know have problems.
I am sure there are more models with
problems, and I'm sure that this company
will rebrand and leave the problems
there and just sell under another name.
So, let's narrow it down to what can you
do about this, or what should you choose
instead? Obviously, big names like
Cisco, PaloAlto are good firewalls, but
probably not targeted at any of the
consumers that may be watching this. And
I know I got a pretty techsavvy crowd
that works a lot in the tech space, but
you're looking for something for home
and those come with pretty steep
licensing fees. Open sense and pfSense,
I think, are both reasonable options.
They're both open source. Well, PFSense,
as long as you're using the community
edition. I'm not going to get into the
nuance of that, but I've done videos on
that topic. Then they have the routers
they sell. If you want to buy something
directly from the folks over at Netgate,
come preloaded with PFSense. Notice I
said NetGate, not Netgear. Two different
companies. people confuse them
occasionally, but Netgear is the company
I pointed out how to back door. Netgate
sells hardware with PFSense on it. But
the other one I'd recommend still would
be UniFi. I think they make a good
product. I know a lot of people ask
about TPLink. I've done videos in the
past on them and I'm working on some
updated videos because TPLink is well
made a lot of empty security promises,
still doesn't have a bug bounty program
and has such a wide product base that
they do have a lot of CVE and sometimes
have not been great with security
researchers. So, I don't really trust
them. There's not a smoking gun that I
know of where someone has found a back
door in a TPLink or even in Romada, but
they don't have the absolute best track
record on security. And with their
prices not being substantially less than
something like Ubiquiti, I don't really
see them as a good option. That's my
personal opinion. Feel free to take that
or don't. I've used a lot of Ubiquiti.
I've used very little uh TP Link and
what I have used I did find quite buggy.
But like I said, this is my opinion.
Feel free to uh make your own judgments
on that. For those of you that are a
little bit more techsavvy that want to
reload something, OpenWRT I think is a
solid choice as well. I've been
following that project for a while. I've
actually been working on potentially
some videos on it because I think it's a
good open source alternative for people
looking to use and build their own
routers on something that's Linux based
out there because there's just not a
whole lot of other open source projects
for the Linux firewall world. But
hopefully this raised a little bit
awareness. Have you uh looked at any of
these routers before? Do you have one?
Hopefully not. Or do you have family
members that have them? Please get them
off of these because there's not a patch
or a firmware update for this. It's
baked into the firmware. Avoid all these
different routers at all costs. And uh
hopefully we don't see them on Amazon.
Maybe Amazon will do a better job of
policing it, but I'm not going to really
hope on that. I am impressed that they
actually have them not for sale, but of
course I don't know if Amazon did that
or if the other company did. But leave
your thoughts and comments down below.
Links to the research are also in the
description. Thanks,
[music]
>> [music]