Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2026-74232cve-2026-74233
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    VulnCheck has identified two previously undocumented factory implants in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Each implant grants an unauthenticated remote attacker the ability to execute commands as root on affected devices, according to the firm's zero-day research team.

    The two implants, dubbed SPEAKINGSTONE and DARKLANTERN, are being tracked as CVE-2026-74232 and CVE-2026-74233, respectively. These are not post-exploitation backdoors added after the fact; they are present in the factory firmware itself, meaning devices ship with the vulnerabilities already in place.

    The implications are significant for any organization using ZBT hardware in their network infrastructure:

    • Both implants allow remote code execution with root privileges, bypassing authentication entirely.
    • Because the flaws are embedded in the firmware at the manufacturing stage, standard patching or reimaging may not remove them unless a vendor-supplied update specifically addresses the issue.
    • Attackers exploiting these flaws would gain full control over the router, enabling traffic interception, persistent access, or use of the device as a pivot point into the broader network.

    At the time of writing, no vendor response or patching timeline has been mentioned in the report. Organizations using ZBT routers should treat them as untrusted and consider isolating them from sensitive network segments until a fix is confirmed.

    Source: The Hacker News

    Is your organization currently running any ZBT-based hardware, and if so, what steps are you taking to mitigate exposure while awaiting an official fix?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World