← All articles

China-made ZBT routers ship with factory backdoors granting unauthenticated root

Researchers at VulnCheck found two undocumented factory implants in the firmware of routers made by the Chinese manufacturer ZBT, each giving a remote, unauthenticated attacker the ability to run commands as root. Named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, both scored around 9.3, require no privileges or interaction. SPEAKINGSTONE runs as a hidden service and beacons out over a fixed UDP port to a hardcoded command-and-control server; because it dials outward, it works from behind network address translation and normal egress filtering. The findings underscore the supply-chain risk of low-cost networking hardware with opaque firmware.

Check
Identify any ZBT or Zbtlink routers in your environment, isolate or replace affected models, and block outbound traffic to the implant's command-and-control server and its fixed UDP port.
Affected
Anyone operating affected ZBT-manufactured routers, including rebranded models; the built-in implants let a remote unauthenticated attacker gain root, and one beacons out to a hardcoded server, working even from behind NAT.
Fix
Replace untrustworthy OEM networking gear, segment and monitor such devices, block known implant command-and-control destinations, inspect egress for beaconing on the implicated port, and prefer vendors with transparent, verifiable firmware.