Find notable cyber news and cases, enriched with sources, timelines, and signals.

ZBT router firmware factory implants (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

VulnCheck disclosed two previously undocumented factory implants in ZBT router firmware, exposing affected devices to unauthenticated root command execution. The implants are tracked as CVE-2026-74232 and CVE-2026-74233 and affect routers built by Shenzhen Zhibotong Electronics (ZBT). One implant, SPEAKINGSTONE, uses a hardcoded C2 path, while DARKLANTERN listens on UDP/9992 with weak authentication. Public evidence shows exposed devices and proof-of-concept status for CVE-2026-74233, making the flaw set operationally risky for deployed routers.

Related Happenings

Zbtlink router firmware unauthenticated root-shell backdoor ENDLESSDOORS security flaw

Vulnerability
H score16 First: 06.08.2026 11:05 Last: 06.08.2026 11:05 Sources 1

About this happening: A factory-shipped backdoor in Zbtlink router firmware exposes at least 20 router models to unauthenticated root shell access. The implant, named ENDLESSDOORS,...

NSA/FBI/CISA router hardening advisory

Advisory/Mitigation
H score33 First: 13.07.2026 12:32 Last: 13.07.2026 12:32 Sources 1

About this happening: NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...

Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw

Vulnerability
H score0 First: 19.06.2026 21:37 Last: 19.06.2026 21:37 Sources 1

About this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...

Timeline

  1. 28.08.2026 13:58 1 articles · 1h ago

    392 devices report to the SPEAKINGSTONE backup domain

    Victim Impact Update

    As of August 21, VulnCheck had seen 392 unique devices report in to the SPEAKINGSTONE backup domain, with 390 in China; it said 83 percent were on China Mobile's network, 304 of the 392 broadcast SSIDs beginning with "CMCC", and 363 self-reported the L3_V2_8 model running firmware 3.0.0.4.528.

    Show sources
  2. 28.08.2026 13:58 2 articles · 1h ago

    VulnCheck discloses SPEAKINGSTONE and DARKLANTERN in ZBT router firmware

    Initial Disclosure

    VulnCheck disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT): SPEAKINGSTONE and DARKLANTERN, tracked as CVE-2026-74232 and CVE-2026-74233. VulnCheck said each implant lets an unauthenticated remote attacker execute commands as root on affected devices, and the disclosure included IoCs plus Suricata and YARA rules.

    Show sources