China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

August 28, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Users of Zbtlink and white-labeled ZBT routers
Incident: Discovery of two factory-installed firmware implants (CVE-2026-74232, CVE-2026-74233) in ZBT routers.
Impact: Unauthenticated remote attackers can execute arbitrary commands as root, exfiltrate credentials, and hijack DNS.
Attacker: Unidentified threat actors
Analysis: Research has uncovered two distinct implants, SPEAKINGSTONE and DARKLANTERN, embedded in ZBT router firmware. One acts as a phone-home C2 beacon for surveillance, while the other opens a backdoor for direct inbound attacks. Both vulnerabilities provide unauthenticated root access, enabling complete device takeover and network exfiltration.
Recommendations: Replace affected ZBT and white-labeled routers with trusted hardware; Implement strict egress and ingress filtering on UDP ports 10000 and 9992; Audit network edge devices for unauthorized firmware implants and beacons
Source: The Hacker News / VulnCheck

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *