China-Made ZBT Routers Contain Implants Allowing Root Access to Unauthenticated Attackers
Security researchers have uncovered two hidden implants in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT), enabling unauthenticated remote attackers to execute commands with root-level access. These implants, named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, were discovered by VulnCheck. Both vulnerabilities scored 9.3 on the CVSS 4.0 scale and 9.8 on CVSS 3.1, indicating their critical severity.
SPEAKINGSTONE operates as the service yunmgrd and sends UDP beacons to a hardcoded command-and-control (C2) server, allowing attackers to execute arbitrary commands, exfiltrate credentials, and hijack DNS. DARKLANTERN, running as infosrvd, opens UDP port 9992 to inbound connections without effective authentication. VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries between August 18-21, 2026.
The implants were found on an $88 Deep Orange router purchased from a U.S. supplier, which uses ZBT firmware built in 2019. Multiple ZBT router models are affected, including WE826-T2, WE2426-C, and L3_V2_8. VulnCheck has not yet identified fixed firmware versions, leaving many devices vulnerable. The company confirmed the implants ship with ZBT firmware, though MOFI Network’s custom firmware was found to be unaffected.
VulnCheck recommends blocking traffic to UDP ports 9992 and 10000, treating router LANs as untrusted, and monitoring for Indicators of Compromise (IoCs). ZBT has not publicly addressed these vulnerabilities, though its firmware download pages remain active as of August 28, 2026. The discovery highlights supply chain risks in network hardware.
- ZBT routers contain two implants allowing unauthenticated root access.
- SPEAKINGSTONE and DARKLANTERN vulnerabilities scored 9.3 and 9.8 on CVSS scales.
