China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck reveals two factory-installed backdoors—SPEAKINGSTONE and DARKLANTE—in ZBT router firmware granting unauthenticated root access, raising serious hardware supply-chain concerns for European network operators.
Summary written by editorial AI · Source link below
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.
The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
Editorial Analysis
Factory-implanted backdoors in networking equipment undermine every downstream security control and call into question hardware procurement practices across European supply chains.
Identify any ZBT-manufactured or white-label routers in your infrastructure, isolate affected devices, and begin hardware replacement planning.
Routers from a Chinese manufacturer ship with pre-installed backdoors—a hardware supply-chain risk that demands immediate procurement review.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the OT/IoT Security Desk
- SecDT: A Profile-Based Security Layer for TRDP Communications4d
- [NEU] [hoch] Hitachi Energy RTU500: Mehrere Schwachstellen4d
- [NEU] [hoch] Rockwell Automation FactoryTalk Activation Manager und Historian Machine Edition: Mehrere Schwachstellen5d
- [NEU] [mittel] Rockwell Automation ControlLogix 5580, CompactLogix 5380, und CompactLogix 5480: Mehrere Schwachstellen ermöglichen Denial of Service5d
- Forescout Research Tests Whether AI Can Create PLC Attacks6d