ZBT router firmware hides twin root access implants

VulnCheck found two factory implants in ZBT router firmware that give unauthenticated attackers root access.

CSBadmin
2 Min Read

Two undocumented factory implants have turned up in firmware for routers made by Shenzhen Zhibotong Electronics, better known as ZBT, researcher VulnCheck said this week. Both give an unauthenticated remote attacker root command execution on affected devices. Tracked as CVE-2026-74232 and CVE-2026-74233, the backdoors, named SPEAKINGSTONE and DARKLANTERN, each carry severity scores of 9.3 under CVSS 4.0 and 9.8 under CVSS 3.1.

SPEAKINGSTONE masquerades as the yunmgrd service, beacons to a hardcoded command-and-control host on UDP port 10000, and stays operational behind NAT and typical egress filtering. The command surface is broad: root-level execution, WAN PPPoE credential capture, DNS hijack list edits and reverse SSH tunneling all sit within its reach. VulnCheck sums it up as a surveillance implant that reaches root on anything it infects.

For DARKLANTERN, the infosrvd service listens on UDP port 9992, and the out-of-box firewall leaves that port reachable from any address. Access checks on the service can be waved through: a baked-in salt and an all-zero wildcard MAC defeat the address validation it performs. VulnCheck’s scan between August 18 and 21 turned up 203 DARKLANTERN devices exposed to the internet, spread across 22 countries, with 16 different models identifying themselves.

VulnCheck found both backdoors on an $88 Deep Orange 3G/4G/LTE router purchased from a US seller, a white-labeled ZBT-WE826-T2 that shipped with 2019 firmware. The discovery precedes the earlier ENDLESSDOORS backdoor disclosures. Organizations running ZBT hardware should assume full compromise, quarantine the devices, and swap them for equipment from vendors that publish verifiable firmware builds.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.