China-manufactured routers from Shenzhen Zhibotong Electronics (ZBT) have been identified with significant security vulnerabilities. According to VulnCheck, two factory-installed implants found in ZBT routers allow remote attackers to execute commands with root privileges. These vulnerabilities, tracked as CVE-2026-74232 and CVE-2026-74233, pose a severe risk to affected devices.
Critical Vulnerabilities Uncovered
VulnCheck has revealed two critical implants, SPEAKINGSTONE and DARKLANTERN, embedded in ZBT router firmware. These implants enable remote command execution without the need for authentication. The vulnerabilities received high severity scores of 9.3 and 9.8 on the CVSS 4.0 and 3.1 scales, respectively, due to their ease of exploitation.
SPEAKINGSTONE, running as the ‘yunmgrd’ service, communicates with a command-and-control server using UDP port 10000. It allows attackers to perform various harmful actions, including executing commands as root and hijacking DNS settings. Meanwhile, DARKLANTERN operates on UDP port 9992 and is accessible to any internet source, making its authentication measures ineffective.
Global Impact of Security Flaws
From August 18 to August 21, VulnCheck identified 203 instances of DARKLANTERN across 22 countries. These routers were traced back to the ZBT-WE826-T2 model, purchased from a U.S. supplier, highlighting the global distribution of potentially compromised devices. SPEAKINGSTONE was found to have a hardcoded backup domain, which VulnCheck subsequently registered, revealing 392 unique devices reporting to it.
The vulnerabilities are notably present in various ZBT router models, including WE1326, WE357, and WE5926, across several firmware builds. This complexity complicates users’ ability to determine if their devices are affected, as no fixed firmware release has been announced.
Preventive Measures and Responses
VulnCheck advises users to block suspicious network traffic and treat LAN connections on these devices as untrusted. Specific rules for monitoring traffic have been published to help identify and mitigate potential threats. ZBT’s previous statement regarding the ENDLESSDOORS component, used for after-sales support, has not addressed the current implants, leaving users seeking clarity.
While ZBT has yet to issue a public response to these findings, the situation underscores the importance of securing router firmware against unauthorized access. Users are encouraged to remain vigilant and apply network security best practices to protect their devices.
As the cybersecurity community continues to analyze these threats, further updates are anticipated to address user concerns and enhance device security.
