China-Made ZBT Routers Vulnerable to Two Factory-Implanted Backdoors Enabling Root Access
China-Made ZBT routers contain two undocumented factory implants (CVE-2026-74232 and CVE-2026-74233) enabling unauthenticated root access through hardcoded C2 servers and weak authentication mechanisms. The vulnerabilities affect multiple router models with CVSS scores of 9.3 and 9.8, allowing command execution, DNS hijacking, and reverse SSH tunnels.
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.
The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
*** END OF TRANSMISSION ***