Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Made Routers Exposed to Critical Security Breaches

China-Made Routers Exposed to Critical Security Breaches

Posted on August 28, 2026 By CWS

China-manufactured routers from Shenzhen Zhibotong Electronics (ZBT) have been identified with significant security vulnerabilities. According to VulnCheck, two factory-installed implants found in ZBT routers allow remote attackers to execute commands with root privileges. These vulnerabilities, tracked as CVE-2026-74232 and CVE-2026-74233, pose a severe risk to affected devices.

Critical Vulnerabilities Uncovered

VulnCheck has revealed two critical implants, SPEAKINGSTONE and DARKLANTERN, embedded in ZBT router firmware. These implants enable remote command execution without the need for authentication. The vulnerabilities received high severity scores of 9.3 and 9.8 on the CVSS 4.0 and 3.1 scales, respectively, due to their ease of exploitation.

SPEAKINGSTONE, running as the ‘yunmgrd’ service, communicates with a command-and-control server using UDP port 10000. It allows attackers to perform various harmful actions, including executing commands as root and hijacking DNS settings. Meanwhile, DARKLANTERN operates on UDP port 9992 and is accessible to any internet source, making its authentication measures ineffective.

Global Impact of Security Flaws

From August 18 to August 21, VulnCheck identified 203 instances of DARKLANTERN across 22 countries. These routers were traced back to the ZBT-WE826-T2 model, purchased from a U.S. supplier, highlighting the global distribution of potentially compromised devices. SPEAKINGSTONE was found to have a hardcoded backup domain, which VulnCheck subsequently registered, revealing 392 unique devices reporting to it.

The vulnerabilities are notably present in various ZBT router models, including WE1326, WE357, and WE5926, across several firmware builds. This complexity complicates users’ ability to determine if their devices are affected, as no fixed firmware release has been announced.

Preventive Measures and Responses

VulnCheck advises users to block suspicious network traffic and treat LAN connections on these devices as untrusted. Specific rules for monitoring traffic have been published to help identify and mitigate potential threats. ZBT’s previous statement regarding the ENDLESSDOORS component, used for after-sales support, has not addressed the current implants, leaving users seeking clarity.

While ZBT has yet to issue a public response to these findings, the situation underscores the importance of securing router firmware against unauthorized access. Users are encouraged to remain vigilant and apply network security best practices to protect their devices.

As the cybersecurity community continues to analyze these threats, further updates are anticipated to address user concerns and enhance device security.

The Hacker News Tags:China routers, CVE, Cybersecurity, DARKLANTERN, firmware vulnerabilities, network security, security breach, SPEAKINGSTONE, VulnCheck, ZBT routers

Post navigation

Previous Post: Leaked Russian University Records Reveal GRU Cyber Training
Next Post: Cisco Highlights Hidden Risks in AI Model Origins

Related Posts

Rethinking Security for Scattered Spider Rethinking Security for Scattered Spider The Hacker News
Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001) Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001) The Hacker News
Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers The Hacker News
Microsoft 365 Device Code Phishing Targets Over 340 Organizations Microsoft 365 Device Code Phishing Targets Over 340 Organizations The Hacker News
BAS Is the Power Behind Real Defense BAS Is the Power Behind Real Defense The Hacker News
Critical Flaws in Gemini CLI and Claude Code Exposed Critical Flaws in Gemini CLI and Claude Code Exposed The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins
  • China-Made Routers Exposed to Critical Security Breaches
  • Leaked Russian University Records Reveal GRU Cyber Training
  • Global Tech Leaders Rally for Enhanced AI Cyber Defense

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins
  • China-Made Routers Exposed to Critical Security Breaches
  • Leaked Russian University Records Reveal GRU Cyber Training
  • Global Tech Leaders Rally for Enhanced AI Cyber Defense

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark