China-Made ZBT Routers Ship With Two Backdoor Implants Giving Root Access
VulnCheck has disclosed two previously undocumented factory implants embedded in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT), both granting unauthenticated remote attackers root-level command execution on affected devices. Tracked as CVE-2026-74232 and CVE-2026-74233, the implants—dubbed SPEAKINGSTONE and DARKLANTERN—were scored 9.3 on CVSS 4.0 and 9.8 on CVSS 3.1, with attack vectors requiring only network access, no privileges, and no user interaction. The findings come from a $88 Deep Orange 3G/4G/LTE Router (a white-labeled ZBT-WE826-T2 running 2019 firmware) and deepen concerns first raised by VulnCheck's August 5 disclosure of ENDLESSDOORS (CVE-2026-66747), which was found in at least 20 Zbtlink router models.
SPEAKINGSTONE operates as a service named yunmgrd, beaconing outbound over UDP port 10000 to a hardcoded command-and-control server—meaning it functions from behind NAT and standard egress filtering. Its protocol supports message types that execute arbitrary commands as root, exfiltrate WAN PPPoE credentials, manage a DNS hijack list, and open a reverse SSH tunnel. DARKLANTERN runs as infosrvd on UDP port 9992, a port the stock firewall exposes to inbound traffic from any internet address. VulnCheck's advisory describes its authentication as effectively bypassed by a hardcoded salt combined with an all-zero wildcard MAC value. Between August 18 and 21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries self-reporting 16 distinct models. Network defenders can verify exposure by probing these ports with a port scanner and reviewing egress logs for anomalous UDP 10000 traffic to unfamiliar hosts via a WHOIS lookup.
The affected footprint spans multiple vendors. DARKLANTERN (CVE-2026-74233) impacts Zbtlink models WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108 and WG3526 on firmware 19.1101, among others including CTN720-W1, LF-1541, MT7620N and WRC1 under an unidentified vendor. SPEAKINGSTONE (CVE-2026-74232) targets Zbtlink L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, MoreQuick MQAC/MQAP series, and AP/HC/HK/MAP models from additional OEMs. VulnCheck, operating as a CVE Numbering Authority, labeled the implants a "surveillance implant with root access to every device it runs on." Given the surveillance-grade capabilities—including PPPoE credential theft and DNS hijacking—operators of these routers should immediately retire or isolate them and run a privacy checkup on any network that previously routed through an affected unit.