← Back to blog

ZBT Routers Found Shipping With Pre-Installed Root Access Implants

Security researchers uncovered two hidden backdoors in China-made ZBT router firmware that allow unauthenticated attackers to gain root access. These implants pose a severe risk to enterprise network security.

TL;DR

  • VulnCheck discovered two undisclosed implants in ZBT router firmware.
  • Named SPEAKINGSTONE and DARKLANTERN, they enable root-level command execution.
  • Attackers can exploit these without authentication via CVE-2026-74232 and CVE-2026-74233.
  • Devices were shipped with the implants already present from the factory.
  • Enterprises using ZBT routers should audit and remediate affected firmware immediately.

Enterprise networks relying on networking hardware from Shenzhen Zhibotong Electronics (ZBT) face a critical security threat after researchers identified two pre-installed implants in their router firmware. These backdoors, uncovered by VulnCheck's zero-day research team, provide unauthenticated attackers with full root access to affected devices.

The implants, dubbed SPEAKINGSTONE and DARKLANTERN, represent serious supply chain risks due to their embedded presence in the device firmware before reaching end users. Organizations using these routers must act swiftly to assess exposure and mitigate potential unauthorized access.

Technical Breakdown of the Implants

  • SPEAKINGSTONE and DARKLANTERN are hardcoded into the router's firmware during manufacturing.
  • Each implant allows remote command execution as root without requiring any form of authentication.
  • CVE-2026-74232 and CVE-2026-74233 track the vulnerabilities associated with each respective implant.
  • No user interaction or credentials are needed to trigger the malicious functionality.
  • The backdoors operate covertly, making detection difficult without active firmware inspection.

Impact and Recommended Actions for Enterprises

  • Organizations using ZBT routers should verify firmware versions and check for signs of compromise.
  • Immediate mitigation includes replacing affected firmware or isolating vulnerable devices until patching.
  • Supply chain audits are critical when sourcing hardware from lesser-known vendors.
  • Network segmentation and monitoring can help limit lateral movement if exploitation occurs.
  • Engaging with vendor advisories and applying official patches is essential once made available.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

ZBT Routers Found Shipping With Pre-Installed Root Access Implants — Agent Breach Blog | Agent Breach