Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Made Routers Exposed to Critical Security Breaches

China-Made Routers Exposed to Critical Security Breaches

Posted on August 28, 2026 By CWS

China-manufactured routers from Shenzhen Zhibotong Electronics (ZBT) have been identified with significant security vulnerabilities. According to VulnCheck, two factory-installed implants found in ZBT routers allow remote attackers to execute commands with root privileges. These vulnerabilities, tracked as CVE-2026-74232 and CVE-2026-74233, pose a severe risk to affected devices.

Critical Vulnerabilities Uncovered

VulnCheck has revealed two critical implants, SPEAKINGSTONE and DARKLANTERN, embedded in ZBT router firmware. These implants enable remote command execution without the need for authentication. The vulnerabilities received high severity scores of 9.3 and 9.8 on the CVSS 4.0 and 3.1 scales, respectively, due to their ease of exploitation.

SPEAKINGSTONE, running as the ‘yunmgrd’ service, communicates with a command-and-control server using UDP port 10000. It allows attackers to perform various harmful actions, including executing commands as root and hijacking DNS settings. Meanwhile, DARKLANTERN operates on UDP port 9992 and is accessible to any internet source, making its authentication measures ineffective.

Global Impact of Security Flaws

From August 18 to August 21, VulnCheck identified 203 instances of DARKLANTERN across 22 countries. These routers were traced back to the ZBT-WE826-T2 model, purchased from a U.S. supplier, highlighting the global distribution of potentially compromised devices. SPEAKINGSTONE was found to have a hardcoded backup domain, which VulnCheck subsequently registered, revealing 392 unique devices reporting to it.

The vulnerabilities are notably present in various ZBT router models, including WE1326, WE357, and WE5926, across several firmware builds. This complexity complicates users’ ability to determine if their devices are affected, as no fixed firmware release has been announced.

Preventive Measures and Responses

VulnCheck advises users to block suspicious network traffic and treat LAN connections on these devices as untrusted. Specific rules for monitoring traffic have been published to help identify and mitigate potential threats. ZBT’s previous statement regarding the ENDLESSDOORS component, used for after-sales support, has not addressed the current implants, leaving users seeking clarity.

While ZBT has yet to issue a public response to these findings, the situation underscores the importance of securing router firmware against unauthorized access. Users are encouraged to remain vigilant and apply network security best practices to protect their devices.

As the cybersecurity community continues to analyze these threats, further updates are anticipated to address user concerns and enhance device security.

The Hacker News Tags:China routers, CVE, Cybersecurity, DARKLANTERN, firmware vulnerabilities, network security, security breach, SPEAKINGSTONE, VulnCheck, ZBT routers

Post navigation

Previous Post: Leaked Russian University Records Reveal GRU Cyber Training
Next Post: Cisco Highlights Hidden Risks in AI Model Origins

Related Posts

Weedhack Malware Targets Gamers via Fake Minecraft Sites Weedhack Malware Targets Gamers via Fake Minecraft Sites The Hacker News
Apple Widens iOS 18.7.7 Update to Shield Against DarkSword Apple Widens iOS 18.7.7 Update to Shield Against DarkSword The Hacker News
Canadian Arrested for Operating Kimwolf DDoS Botnet Canadian Arrested for Operating Kimwolf DDoS Botnet The Hacker News
Gitea Patches Critical RCE Vulnerability in Git Hooks Gitea Patches Critical RCE Vulnerability in Git Hooks The Hacker News
Identity Security Has an Automation Problem—And It’s Bigger Than You Think Identity Security Has an Automation Problem—And It’s Bigger Than You Think The Hacker News
From Triage to Threat Hunts: How AI Accelerates SecOps From Triage to Threat Hunts: How AI Accelerates SecOps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Agents Exploit Linux Vulnerability on Internal Systems
  • Unitree G1 EDU Robots Face Critical Security Vulnerabilities
  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins
  • China-Made Routers Exposed to Critical Security Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Agents Exploit Linux Vulnerability on Internal Systems
  • Unitree G1 EDU Robots Face Critical Security Vulnerabilities
  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins
  • China-Made Routers Exposed to Critical Security Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark