China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Read full story on The Hacker News
Share
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
AI disclosure

Summary

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.