TechNewsReel
Live

Factory-Installed Implants in ZBT Routers Grant Root Access to Attackers

Security researchers have uncovered two critical implants, SPEAKINGSTONE and DARKLANTERN, embedded in hardware from Shenzhen Zhibotong Electronics.

TechNewsReel Newsroom · August 28, 2026

Security researchers at VulnCheck have disclosed the discovery of two factory-installed implants, SPEAKINGSTONE and DARKLANTERN, embedded in routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These implants allow unauthenticated remote attackers to execute commands with root privileges, granting full control over the affected networking hardware.

The two implants operate with distinct mechanisms to facilitate unauthorized access. SPEAKINGSTONE (CVE-2026-74232) runs as a process named 'yunmgrd' and functions as a command-and-control (C2) beacon. According to VulnCheck, this implant can exfiltrate PPPoE credentials, hijack DNS settings, or open reverse SSH tunnels to bypass network security.

DARKLANTERN (CVE-2026-74233) runs as 'infosrvd' on UDP port 9992, acting as a listener that opens the router's firewall to inbound attacks. VulnCheck identified 203 internet-facing DARKLANTERN instances, including 103 located in the United States.

A Pattern of Embedded Access

This discovery is not an isolated incident for the manufacturer. It follows a previous disclosure by VulnCheck regarding another implant, ENDLESSDOORS (CVE-2026-66747), found in Zbtlink routers. ZBT has a history of white-labeling its devices for various other brands, meaning these vulnerabilities may exist across a wide array of consumer and business hardware under different labels.

When questioned about similar components in the past, ZBT claimed such tools were intended for "after-sales technical support" and "software debugging." However, the capabilities of these implants suggest a purpose far beyond routine maintenance.

Supply Chain Implications

The presence of factory-installed implants represents a severe supply chain risk. Because these tools are integrated at the manufacturing stage, they bypass standard security perimeters like NAT and firewalls. VulnCheck described the discovery as a "surveillance implant with root access to every device it runs on," highlighting the potential for persistent surveillance and remote network manipulation by whoever controls the C2 infrastructure.

For home and business users, this means the very device intended to secure the network is instead providing a backdoor for external actors. The integration of such tools at the firmware level makes detection difficult for the average user and necessitates a high level of trust in the hardware manufacturer—a trust that is undermined by the discovery of these hidden access points.

Future Outlook

As these implants are embedded in the firmware, users are encouraged to monitor for unauthorized traffic on UDP port 9992. While Zbtlink previously asserted that similar components had "never been used for unauthorized access," the critical nature of these vulnerabilities suggests a high risk of exploitation.

Security teams are now tasked with identifying the full scope of ZBT-manufactured hardware in their environments to mitigate the risk of persistent, root-level compromise. Until firmware updates are provided and verified, the most effective mitigation remains the identification and replacement of affected hardware.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.