Submind YouTube summaries
Thumbnail for These Routers Shipped With Backdoor And Amazon Sold Them For Years

These Routers Shipped With Backdoor And Amazon Sold Them For Years

Watch on YouTube

Video summary

On August 5th, 2026, security researchers from Volc published a critical report revealing that numerous routers sold on Amazon contained built-in backdoors designed to actively contact command and control servers on the internet. Although these specific devices were removed from sale by August 7th of the same year, leaving only "currently unavailable" listings behind, the issue extends far beyond just those models. The affected hardware often uses deceptive naming conventions that mimic reputable brands like TP-Link or WaveLink to confuse consumers; for instance, a device branded as ZBT Link was found attempting unauthorized connections despite being placed on an isolated network. This practice is not new, with evidence suggesting such vulnerabilities have existed since at least 2015, relying on the fact that few people scrutinize inexpensive networking equipment until a dedicated security researcher brings it to light. The implications of these findings are severe because many users assume they can avoid backdoors by sticking only to well-known brands like Netgear or TP-Link, yet research indicates that even major manufacturers have faced similar issues in their own products. While the video highlights specific problematic models and namesakes created through wordplay, it emphasizes that an exhaustive list of unsafe devices is impossible to compile due to companies frequently rebranding hardware with existing vulnerabilities under new labels. Consequently, relying solely on brand recognition offers no guarantee of security, as there are likely many other routers circulating in the market with identical hidden flaws that remain undetected until a specific investigation exposes them. For consumers seeking safer alternatives, the video suggests moving away from cheap off-brand devices and considering enterprise-grade solutions or open-source options tailored for home use. Recommended choices include hardware preloaded with OpenSense or pfSense from Netgate, as well as products from Ubiquiti (UniFi), which are praised for their build quality despite some past bugs in specific TP-Link units that lack a bug bounty program and have poor security track records. Tech-savvy users who prefer to customize their own firmware can also look into OpenWRT, an open-source project based on Linux that serves as a robust alternative for building secure routers without relying on proprietary backdoors baked directly into the hardware's operating system. Ultimately, the most critical takeaway is that once these malicious features are embedded in router firmware, there is often no patch or update available to remove them, meaning affected devices must be physically disconnected from any network immediately. The video urges viewers not only to check their own equipment but also to ensure family members do not use routers with known vulnerabilities, as the risk of data theft and unauthorized remote access remains constant without a fix. While Amazon has temporarily stopped selling these specific models, there is no guarantee that similar devices will disappear entirely from online stores or other retailers in the future, making vigilance and informed purchasing decisions essential for maintaining home network security.
Read the full video transcript
On August 5th of 2026, researchers over at Volcublished a list of routers that had built-in back doors being sold on Amazon. Now, good news is it's August 7th of 2026 and they stopped selling them. But that's not the complete story. So, let's look a little bit closer at exactly what they found and how many more problems are probably out there. The title of the blog post is Endless Doors is Phoning Home Pickup. On my desk in suburban Philadelphia, an AX 3000 dual SIM 5G CPE Wi-Fi 6 plugged into an isolated research network. Its status lights blink and twinkle continuously and attempts to reach command and control servers on the internet. So even if you have this behind another firewall, it's reaching out. This isn't like an open port that someone can log into. This device actively reaches out. And the research goes on from there to list out that they are sold under the name ZBT link and why Flyier. I kind of like Flyier. I think it's a cool name. Uh they're sold on stores like ZBTI.com and ZBTLink.com. And if you notice the naming here, AX3000. This is really similar to TPLink's name. So calling it a ZBT link, I think there's a little bit of play on words going. I went to the Amazon store and when I first seen this, I went right to the Amazon store and noticed it was for sale. It's not for sale anymore. They're still listed. They haven't taken down the store. But if you try to purchase any of these models, they all say currently unavailable. They were available as of just the other day. But I just find it really interesting that they have called this the AC1200. Where have I seen that name before? There's a Wavelink AC1200 and probably I think there's some TPLink models that have some similar names. This is part of the problem as well is I'm willing to bet there's lots of other router brands with also very similar names that have the same back door. This has actually been here for years. This isn't anything new. This appears to date all the way back to 2015. The reality of a lot of these inexpensive routers is there's just not a lot of people looking at them. Which is why when someone takes the time to look at it and it's a proper security researcher and they have a place to post a blog to get attention that convergence of things is the only way we know about this. And I know some of you are thinking, well, I don't buy these weird off-brand play on word different routers that I find on Amazon. I stick with brands I know like Netgear Nighthawk. But Wendell did a video back in May of 2026 and a right up here in his forums that I'll leave a link to talking about the back door he found in the Nekar Nighthawk. I believe he also did a video in Gamers Nexus channel about the same topic. And I do want to give a shout out to the low-level channel who also covers this as a topic and found several back doors in different router models and has an entire great breakdown of how to deep dive into these and find these backd doors. Now, there's no reasonable way to make an exhaustive list of everything you shouldn't buy. I just highlighted a couple models that I know have problems. I am sure there are more models with problems, and I'm sure that this company will rebrand and leave the problems there and just sell under another name. So, let's narrow it down to what can you do about this, or what should you choose instead? Obviously, big names like Cisco, PaloAlto are good firewalls, but probably not targeted at any of the consumers that may be watching this. And I know I got a pretty techsavvy crowd that works a lot in the tech space, but you're looking for something for home and those come with pretty steep licensing fees. Open sense and pfSense, I think, are both reasonable options. They're both open source. Well, PFSense, as long as you're using the community edition. I'm not going to get into the nuance of that, but I've done videos on that topic. Then they have the routers they sell. If you want to buy something directly from the folks over at Netgate, come preloaded with PFSense. Notice I said NetGate, not Netgear. Two different companies. people confuse them occasionally, but Netgear is the company I pointed out how to back door. Netgate sells hardware with PFSense on it. But the other one I'd recommend still would be UniFi. I think they make a good product. I know a lot of people ask about TPLink. I've done videos in the past on them and I'm working on some updated videos because TPLink is well made a lot of empty security promises, still doesn't have a bug bounty program and has such a wide product base that they do have a lot of CVE and sometimes have not been great with security researchers. So, I don't really trust them. There's not a smoking gun that I know of where someone has found a back door in a TPLink or even in Romada, but they don't have the absolute best track record on security. And with their prices not being substantially less than something like Ubiquiti, I don't really see them as a good option. That's my personal opinion. Feel free to take that or don't. I've used a lot of Ubiquiti. I've used very little uh TP Link and what I have used I did find quite buggy. But like I said, this is my opinion. Feel free to uh make your own judgments on that. For those of you that are a little bit more techsavvy that want to reload something, OpenWRT I think is a solid choice as well. I've been following that project for a while. I've actually been working on potentially some videos on it because I think it's a good open source alternative for people looking to use and build their own routers on something that's Linux based out there because there's just not a whole lot of other open source projects for the Linux firewall world. But hopefully this raised a little bit awareness. Have you uh looked at any of these routers before? Do you have one? Hopefully not. Or do you have family members that have them? Please get them off of these because there's not a patch or a firmware update for this. It's baked into the firmware. Avoid all these different routers at all costs. And uh hopefully we don't see them on Amazon. Maybe Amazon will do a better job of policing it, but I'm not going to really hope on that. I am impressed that they actually have them not for sale, but of course I don't know if Amazon did that or if the other company did. But leave your thoughts and comments down below. Links to the research are also in the description. Thanks, [music] >> [music]