ZBT router firmware factory implants (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
VulnCheck disclosed two previously undocumented factory implants in ZBT router firmware, exposing affected devices to unauthenticated root command execution. The implants are tracked as CVE-2026-74232 and CVE-2026-74233 and affect routers built by Shenzhen Zhibotong Electronics (ZBT). One implant, SPEAKINGSTONE, uses a hardcoded C2 path, while DARKLANTERN listens on UDP/9992 with weak authentication. Public evidence shows exposed devices and proof-of-concept status for CVE-2026-74233, making the flaw set operationally risky for deployed routers.
Related Happenings
Zbtlink router firmware unauthenticated root-shell backdoor ENDLESSDOORS security flaw
Vulnerability
H score16
First: 06.08.2026 11:05
Last: 06.08.2026 11:05
Sources 1
About this happening:
A factory-shipped backdoor in Zbtlink router firmware exposes at least 20 router models to unauthenticated root shell access. The implant, named ENDLESSDOORS,...
Zbtlink router firmware unauthenticated root-shell backdoor ENDLESSDOORS security flaw
VulnerabilityAbout this happening: A factory-shipped backdoor in Zbtlink router firmware exposes at least 20 router models to unauthenticated root shell access. The implant, named ENDLESSDOORS,...
NSA/FBI/CISA router hardening advisory
Advisory/Mitigation
H score33
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
NSA/FBI/CISA router hardening advisory
Advisory/MitigationAbout this happening: NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
Vulnerability
H score0
First: 19.06.2026 21:37
Last: 19.06.2026 21:37
Sources 1
About this happening:
A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
VulnerabilityAbout this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
Timeline
-
28.08.2026 13:58 1 articles · 1h ago
392 devices report to the SPEAKINGSTONE backup domain
Victim Impact UpdateAs of August 21, VulnCheck had seen 392 unique devices report in to the SPEAKINGSTONE backup domain, with 390 in China; it said 83 percent were on China Mobile's network, 304 of the 392 broadcast SSIDs beginning with "CMCC", and 363 self-reported the L3_V2_8 model running firmware 3.0.0.4.528.
Show sources
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access — thehackernews.com — 28.08.2026 13:58
-
28.08.2026 13:58 1 articles · 1h ago
CISA records proof-of-concept exploitation for CVE-2026-74233
Legal Policy Action UpdateCISA's Vulnrichment record for CVE-2026-74233, dated August 27, rates exploitation as proof of concept, which its documentation defines as a public proof-of-concept existing at the time of analysis.
Show sources
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access — thehackernews.com — 28.08.2026 13:58
-
28.08.2026 13:58 2 articles · 1h ago
VulnCheck discloses SPEAKINGSTONE and DARKLANTERN in ZBT router firmware
Initial DisclosureVulnCheck disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT): SPEAKINGSTONE and DARKLANTERN, tracked as CVE-2026-74232 and CVE-2026-74233. VulnCheck said each implant lets an unauthenticated remote attacker execute commands as root on affected devices, and the disclosure included IoCs plus Suricata and YARA rules.
Show sources
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access — thehackernews.com — 28.08.2026 13:58
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access — thehackernews.com — 28.08.2026 13:58