logo

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

ID: 297b1459-f5a8-5187-a970-725eac4da120

STIX ID: report--297b1459-f5a8-5187-a970-725eac4da120

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** VulnCheck disclosed two undocumented factory implants in ZBT router firmware—SPEAKINGSTONE (outbound UDP 10000 C2, root command execution, exfiltration, reverse SSH) and DARKLANTERN (infosrvd listener on UDP 9992 with weak authentication)—assigned CVE-2026-74232/74233 with high CVSS scores; researchers observed hundreds of devices beaconing or responding, published IoCs (domains, IP, ports, service names, SHA-256 hashes) and recommended blocking relevant ports, treating router LANs as untrusted, and deploying detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.