NewsSecurity Vulnerabilities

Chinese-Made ZBT Routers Found Containing Two Hidden Backdoors

Security researchers have uncovered two previously undocumented backdoors hidden inside the firmware of a range of Chinese-made ZBT routers, potentially allowing unauthenticated attackers to gain root-level access to affected devices.

The discovery was made by cybersecurity researchers at VulnCheck, who identified the two firmware implants as SPEAKINGSTONE and DARKLANTERN.

Both vulnerabilities have been assigned CVE identifiers — CVE-2026-74232 and CVE-2026-74233 — and have been rated as critical security issues.

Remote access without authentication

SPEAKINGSTONE operates as a background service on affected routers and can communicate with a hard-coded command-and-control server.

According to researchers, the implant can accept commands that are executed with root privileges. It can also potentially expose PPPoE credentials, modify DNS-related settings and establish a reverse SSH connection.

Researchers describe SPEAKINGSTONE as particularly concerning because the router can initiate the connection itself, meaning the device does not necessarily need to have an openly accessible management interface.

DARKLANTERN presents another serious risk. The implant operates through UDP port 9992 and provides a remote interface that researchers say can be accessed without effective authentication.

VulnCheck identified 203 internet-facing systems across 22 countries responding to probes for the DARKLANTERN service between 18 and 21 August.

Multiple router models affected

The implants have been discovered across a number of ZBT and Zbtlink models, including the WE826-T2, WE826-Q, WE5926, WE357, WG108 and WG3526, among others.

The problem is made more complicated by the way ZBT hardware is sold.

ZBT manufactures networking equipment that can subsequently be sold by other companies under different brand names. This means customers may be using ZBT hardware without realising that the original manufacturer is ZBT.

Researchers therefore warn that simply checking the brand name printed on a router may not be enough to determine whether a device is affected.

Third backdoor discovered

The latest findings come only weeks after researchers uncovered another factory-installed implant known as ENDLESSDOORS.

That earlier discovery affected at least 20 Zbtlink router models and was found to provide remote access capabilities from the device’s firmware.

The discovery of three separate implants has raised wider concerns about the security of firmware supplied with inexpensive white-label networking equipment.

Security concerns for businesses and consumers

The presence of these components is particularly concerning because they are embedded within router firmware rather than being malware that has been installed later by an attacker.

A compromised router could potentially provide an attacker with a position inside a home or business network, allowing them to monitor network activity, manipulate traffic or potentially access other systems.

VulnCheck has urged organisations to identify ZBT-manufactured equipment within their networks and assess whether affected models and firmware versions are in use.

ZBT has previously stated that its remote-access functionality is intended for authorised technical support and maintenance. The company has also said that its remote access mechanisms do not pose a security risk.

However, researchers argue that the lack of effective authentication and the ability to execute commands with root privileges create significant security concerns.

What should users do?

Anyone using a ZBT or Zbtlink router should check the exact model number and firmware version of their device.

Businesses should also consider checking equipment purchased under other brand names, as ZBT hardware is widely resold and rebranded.

Where an affected device cannot be securely updated or verified, replacing the router may be the safest option.

The discoveries highlight an increasingly important cybersecurity issue: network equipment can represent a significant security risk even before an attacker gains access to it.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.