China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Overview
VulnCheck has identified two serious vulnerabilities in routers produced by Shenzhen Zhibotong Electronics (ZBT). These vulnerabilities, labeled as SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to gain root access to the affected devices. This means that anyone with knowledge of these implants can execute commands on the routers without needing any credentials. The vulnerabilities are associated with CVE-2026-74232 and CVE-2026-74233. Given the widespread use of ZBT routers, this poses a significant risk to users, potentially compromising their networks and sensitive data. Users of these routers should take immediate action to secure their devices.
Key Takeaways
- Affected Systems: Routers manufactured by Shenzhen Zhibotong Electronics (ZBT), specifically those running the affected firmware.
- Action Required: Users should immediately check for firmware updates from ZBT and apply any available patches.
- Timeline: Newly disclosed
Original Article Summary
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
Impact
Routers manufactured by Shenzhen Zhibotong Electronics (ZBT), specifically those running the affected firmware.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should immediately check for firmware updates from ZBT and apply any available patches. If no patches are available, users should consider isolating affected devices from their networks and changing default credentials to enhance security.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Zero-day.