Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Sunsets, disasters, dinners: we now record them all with our phones. But what is that doing to our souls? | Phoebe Greenwood

    August 29, 2026

    Did Disney buy Dollywood? Claim is pure fantasy

    August 29, 2026

    Israeli settlers surround Palestinian home in occupied West Bank’s Qusra | Israel-Palestine conflict News

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Sunsets, disasters, dinners: we now record them all with our phones. But what is that doing to our souls? | Phoebe Greenwood
    • Did Disney buy Dollywood? Claim is pure fantasy
    • Israeli settlers surround Palestinian home in occupied West Bank’s Qusra | Israel-Palestine conflict News
    • Ein Spaziergang mit Manuela Schwesig – POLITICO
    • Carney Has Canadians’ Support on Trump. Now Comes the Hard Part.
    • Soundcore Liberty 5 Pro Review: Master of Phone Calls
    • China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
    • Bitcoin Traders Watch Fed Chair Warsh for Clues—And Get Nothing
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.

    The implants, named SPEAKINGSTONE and DARKLANTERN by the company’s zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

    VulnCheck, which assigned both identifiers as a CVE Numbering Authority (CNA), rated each 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1. Both vectors record a network attack requiring no privileges and no user interaction.

    SPEAKINGSTONE, which runs as the service yunmgrd, sends beacons over UDP port 10000 to a hardcoded command-and-control (C2) server. Because the implant dials outward, it functions from behind NAT and ordinary egress filtering.

    Its protocol supports message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel.

    “This is a surveillance implant with root access to every device it runs on,” VulnCheck said in its supply chain research.

    DARKLANTERN operates as the service infosrvd on UDP port 9992, which the router’s stock firewall opens to inbound connections from any internet address. VulnCheck’s advisory describes the service’s authentication as ineffective, resting on a hardcoded salt and an all-zero wildcard MAC value that bypasses its own address check.

    Cybersecurity

    Between August 18 and August 21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries, self-reporting 16 distinct models. The figure counts hosts that answered a probe rather than devices found compromised.

    Both implants were found on an $88 Deep Orange 3G/4G/LTE Router bought from a U.S. supplier, a white-labeled ZBT-WE826-T2 whose firmware was built in 2019. That unit predates ENDLESSDOORS (CVE-2026-66747), the phone-home implant VulnCheck disclosed on August 5 and found in at least 20 Zbtlink router models.

    VulnCheck’s advisory for the DARKLANTERN command injection and its advisory for the SPEAKINGSTONE C2 implant name the following models and firmware builds –

    • CVE-2026-74233 (DARKLANTERN) – Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108 and WG3526 on firmware 19.1101, WE2426-C on 19.1112, WE5926-EC_QP on 20.0516 and WF3526-P on 19.051, plus CTN720-W1, LF-1541 and MT7620N on 19.1101 and WRC1 on 20.0622, which the CVE record lists under an unidentified vendor.
    • CVE-2026-74232 (SPEAKINGSTONE) – Zbtlink L3_V2_8 on 3.0.0.4.528, WE826-T2 on 19.1101, ZBT-7628 on 1.0.0.2.007 and ZBT-ZBT7621 on 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A and MQAP-7628 on 1.0.0.2.000, and AP522 on 1.0.0.2.014, AP7628 and HC5661A on 3.0.0.4.380, APG721B on 19.0809, HK300 on 1.0.0.2.032 and MAP-N10 on 1.0.0.2.044 under an unidentified vendor.

    The advisory pages display those builds as upper bounds, while the CVE records name each firmware as a single exact build and set the default status of every other version to unknown. Neither advisory names a fixed firmware release, leaving an owner on a build outside the listed set without a published basis for deciding whether the flaw applies.

    Model number rather than brand is the reliable check, because ZBT sells the same hardware and firmware to resellers that put their own name on the case. The Hacker News confirmed via the IEEE-registered MAC prefix database on August 28 that the blocks 78:A3:51 and F8:5E:3C are both assigned to Shenzhen Zhibotong Electronics, letting an owner identify the manufacturer from the device’s own address.

    SPEAKINGSTONE carries a hardcoded backup C2 domain that the implant reaches for where a primary server was never configured, and VulnCheck found that domain unregistered.

    The company registered the domain and stood up a server running a reverse-engineered implementation of the protocol. Beacons began arriving as soon as the server was live.

    As of August 21, 392 unique devices had reported in, of which 390 were in China. VulnCheck said 83 percent were on China Mobile’s network, that 304 of the 392 broadcast SSIDs beginning with “CMCC”, and that 363 self-reported a single model, L3_V2_8, running firmware 3.0.0.4.528.

    Because a device reaches the backup domain only where a primary C2 was never configured, the 392 are a floor drawn from an unrepresentative subset rather than a count of affected devices.

    VulnCheck flags CVE-2026-74233 in its own Known Exploited Vulnerabilities catalog, whose published criteria require that a vulnerability be “publicly-reported as exploited in the wild.”

    CISA’s Vulnrichment enrichment, recorded against the same CVE on August 27, rates exploitation as proof of concept, which the agency’s documentation defines as a public proof-of-concept existing at the time of analysis. The Hacker News confirmed via CISA’s Known Exploited Vulnerabilities catalog, version 2026.08.27, that none of the three ZBT CVEs appear in it as of August 28.

    VulnCheck published the following indicators of compromise (IoCs) –

    • Domains – www.ac-link[.]com, the SPEAKINGSTONE primary C2, and www.findmyipaddr[.]com, the backup domain VulnCheck registered
    • IP address – 47.107.224[.]89, an Alibaba Cloud address in Shenzhen that the primary C2 domain still resolved to when The Hacker News checked on August 28
    • Ports – UDP/9992 inbound for DARKLANTERN, UDP/8897 for its responses, and UDP/10000 outbound for SPEAKINGSTONE beacons
    • Services and paths – infosrvd, yunmgrd, inetdetect, /etc/exec/cmd, /tmp/info.txt and /tmp/yunclient.conf
    • SHA-256 hashes – b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818 (yunmgrd), 7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245 (infosrvd) and ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926 (inetdetect)

    VulnCheck’s guidance for the earlier implant was to block and alert on the endpoints at both the egress and the resolver, and to treat the router’s LAN as untrusted.

    Because DARKLANTERN listens on UDP/9992, blocking inbound traffic to that port at the network edge closes off the listener while a fixed release is outstanding.

    VulnCheck published Suricata and YARA rules alongside the research, one of which alerts on DARKLANTERN command output arriving on UDP port 8898 while the accompanying text and scanner both use 8897.

    Cybersecurity

    Zbtlink addressed the earlier ENDLESSDOORS component in a statement on its website, saying it serves solely as an after-sales technical support tool used only on a customer’s explicit request and authorization.

    “This component has never been used for unauthorized access,” the company said.

    A Zbtlink spokesperson told The Hacker News on August 6 that the feature is “solely intended” for after-sales maintenance and serves no other purposes.

    “It is generally retained only on sample units to assist customers with software debugging,” the spokesperson added.

    That statement addresses ENDLESSDOORS alone, and Zbtlink has issued no public statement on yunmgrd or infosrvd.

    The Hacker News found on August 28 that the company’s firmware download pages were live and serving eight images dated August 17, among them builds for the WE826-T2 and WE2426-C, both named in the new advisories.

    VulnCheck said the implants ship with ZBT firmware, and pointed to MOFI Network, which develops its own firmware for the same platform and whose examined image was free of the three implants.

    The Hacker News has reached out to Zbtlink for comment on whether its current firmware still contains the two components, and to VulnCheck for the evidence behind its catalog listing, and will update this story with any response.

    access Attackers ChinaMade giving Implants Root routers Ship unauthenticated ZBT
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hasbro Data Breach Exposed Employee Personal Information

    Windows 11 KB5120998 update released with 35 changes and fixes

    ServiceNow warns of three max severity security vulnerabilities

    Toy-making giant Hasbro disclose data breach affecting employees

    Key Reasons Why Identity Fabric Matters in 2026

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Sunsets, disasters, dinners: we now record them all with our phones. But what is that doing to our souls? | Phoebe Greenwood

    August 29, 2026

    Did Disney buy Dollywood? Claim is pure fantasy

    August 29, 2026

    Israeli settlers surround Palestinian home in occupied West Bank’s Qusra | Israel-Palestine conflict News

    August 29, 2026

    Ein Spaziergang mit Manuela Schwesig – POLITICO

    August 29, 2026
    Latest Posts

    Chart of the Week: Outside groups spend millions on House primaries • OpenSecrets

    July 30, 2026

    NASA Webb Explores Family Tree of Newly Discovered Distant Objects

    July 30, 2026

    There’s a New Way to Protect Bitcoin From Future Quantum Attacks, Researchers Say

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Sunsets, disasters, dinners: we now record them all with our phones. But what is that doing to our souls? | Phoebe Greenwood

    August 29, 2026

    Did Disney buy Dollywood? Claim is pure fantasy

    August 29, 2026

    Israeli settlers surround Palestinian home in occupied West Bank’s Qusra | Israel-Palestine conflict News

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.