<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access]]></title><description><![CDATA[<p dir="auto">VulnCheck has identified two previously undocumented factory implants in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Each implant grants an unauthenticated remote attacker the ability to execute commands as root on affected devices, according to the firm's zero-day research team.</p>
<p dir="auto">The two implants, dubbed <strong>SPEAKINGSTONE</strong> and <strong>DARKLANTERN</strong>, are being tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-74232" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-74232</a></strong> and <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-74233" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-74233</a></strong>, respectively. These are not post-exploitation backdoors added after the fact; they are present in the factory firmware itself, meaning devices ship with the vulnerabilities already in place.</p>
<p dir="auto">The implications are significant for any organization using ZBT hardware in their network infrastructure:</p>
<ul>
<li>Both implants allow remote code execution with root privileges, bypassing authentication entirely.</li>
<li>Because the flaws are embedded in the firmware at the manufacturing stage, standard patching or reimaging may not remove them unless a vendor-supplied update specifically addresses the issue.</li>
<li>Attackers exploiting these flaws would gain full control over the router, enabling traffic interception, persistent access, or use of the device as a pivot point into the broader network.</li>
</ul>
<p dir="auto">At the time of writing, no vendor response or patching timeline has been mentioned in the report. Organizations using ZBT routers should treat them as untrusted and consider isolating them from sensitive network segments until a fix is confirmed.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently running any ZBT-based hardware, and if so, what steps are you taking to mitigate exposure while awaiting an official fix?</p>
]]></description><link>https://xploitlk.com/topic/146/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:08 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/146.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 29 Aug 2026 20:30:29 GMT</pubDate><ttl>60</ttl></channel></rss>