Chinese-made routers, sold on Amazon and eBay, contain hidden backdoor and are being exploited by Mirai malware and other methods

CyberNews.com’s Investigations team today announced that they have identified hidden backdoors in Chinese-manufactured routers that share common firmware, with evidence that the routers are being exploited by the Mirai malware. In a collaboration between CyberNews.com Senior Information Security Researcher Mantas Sasnauskas and researchers James Clee and Roni Carta, the team found that routers sold by Amazon, eBay and Walmart are all affected, and vulnerabilities are already being exploited.

The two brands identified are, Wavlink routers that are available on eBay and also highlighted as an Amazon Choice Router, and Jetstream routers which are sold exclusively at Walmart. 

These critical vulnerabilities allow attackers to remotely control the routers as well as any device connected to that network and monitor all the traffic coming through that router. It's akin to constant surveillance on your personal network, with someone watching all your activity and stealing all your information. Additionally, the Wavlink routers contain a script that lists nearby wifi and has the capability to compromise those networks.

CyberNews has already detected multiple malicious attempts from a Chinese IP address, which is trying to upload and execute a harmful script on the routers. After investigating the suspicious file, the investigation team has identified that is part of the infamous Mirai botnet.

The Mirai botnet has been responsible for multiple major attacks, including a large-scale DDoS attack in 2016 that left much of the internet inaccessible on the US East coast.

“After my initial findings on the first router I purchased, I bought two more repeaters off Amazon,” said Clee. “Although they are very different physically and slightly different technically, all three had almost the exact same exploit chain. It's hard to make sweeping, definitive statements, but given that all three had the same flaws I’d suspect that many more Wavlink devices are the same.”

When CyberNews.com attempted to find information on the companies behind these routers, it appears that both Jetstream and Wavlink are subsidiaries of a Shenzhen-based company known as Winstars Technology Ltd, which reportedly exports 1-2M pieces per month.

To date, none of the retailers or manufacturers involved have responded to the findings.

Researchers Clee and Carta are in agreement that the backdoors found are intentional. “This is not a mistake,” Carta asserts. “Someone had to take the decision to make the password client-side. A human conceived this code knowing that this would be accessible from an unauthenticated user. Now, the question is why?”

“The fact that there’s a GUI for RCE, and the fact that a page was established to validate a password outside of the existing authentication mechanisms, leads me to believe that neither were an accident, Clee said.”

Mantas Sasnauskas, a Senior Researcher on CyberNews.com’s Investigations team, said “We are working hard to see if we can identify any active exploitation, as the investigation has revealed the vulnerabilities of these routers are being exploited by the Mirai malware. Such vulnerabilities in Chinese hardware or software can’t be discussed without acknowledging the Chinese government’s position on national and international surveillance.

Chinese data retention laws force Chinese companies, or companies operating in China, to keep data on servers located inside the country – and to provide practically unrestricted access to that data to law enforcement. This includes even encrypted data, with the Chinese government requiring access to decryption keys.” He continued, “This type of undocumented backdoor access is a major reason that the United States, Germany, and other governments around the world banned Huawei when they found that the Chinese company could secretly access sensitive information for devices that it sold.”

Existing customers are advised to stop using Jetstream and Wavlink routers, temporarily shut down the network, clean computers, and reset computer passwords and logins for online accounts to protect themselves, their families and their neighbors.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.