{"id":2592,"date":"2026-08-28T15:04:29","date_gmt":"2026-08-28T15:04:29","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2592"},"modified":"2026-08-28T15:04:29","modified_gmt":"2026-08-28T15:04:29","slug":"china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2592","title":{"rendered":"China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh0i2viN2zKBeSxzTqoxZkPNq_6lPMDBLb18zbLPwufsY4mFm494ydDDAWi6gGwy6PsmRGublHFmdmcEiGKViLuUgaJwWux_YUW7HQHuGbbf04HGNpoZa6QLmvf1IHE04TeTT89Yc1_jo0z6mptCbX-fIhVEVQzg5GnfU2Uya4HHASHbttTBGMxl7KMkbM\/s1700-e365\/router-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (<b>ZBT<\/b>), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.<\/p>\n<p>The implants, named <b>SPEAKINGSTONE<\/b> and <b>DARKLANTERN <\/b>by the company&#8217;s zero-day research team, are tracked as <b>CVE-2026-74232<\/b> and <b>CVE-2026-74233<\/b>.<\/p>\n<p>VulnCheck, which assigned both identifiers as a CVE Numbering Authority (CNA), rated each 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1. Both vectors record a network attack requiring no privileges and no user interaction.<\/p>\n<p>SPEAKINGSTONE, which runs as the service <code>yunmgrd<\/code>, sends beacons over UDP port 10000 to a hardcoded command-and-control (C2) server. Because the implant dials outward, it functions from behind NAT and ordinary egress filtering.<\/p>\n<p>Its protocol supports message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel.<\/p>\n<p>\u00abThis is a surveillance implant with root access to every device it runs on,\u00bb VulnCheck said in <a href=\"https:\/\/www.vulncheck.com\/blog\/zbt-darklantern-speakingstone\">its supply chain research<\/a>.<\/p>\n<p>DARKLANTERN operates as the service <code>infosrvd<\/code> on UDP port 9992, which the router&#8217;s stock firewall opens to inbound connections from any internet address. VulnCheck&#8217;s advisory describes the service&#8217;s authentication as ineffective, resting on a hardcoded salt and an all-zero wildcard MAC value that bypasses its own address check.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Between August 18 and August 21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries, self-reporting 16 distinct models. The figure counts hosts that answered a probe rather than devices found compromised.<\/p>\n<p>Both implants were found on an $88 Deep Orange 3G\/4G\/LTE Router bought from a U.S. supplier, a white-labeled ZBT-WE826-T2 whose firmware was built in 2019. That unit predates ENDLESSDOORS (CVE-2026-66747), the phone-home implant VulnCheck disclosed on August 5 and found in at least <a href=\"https:\/\/thehackernews.com\/2026\/08\/chinese-made-zbtlink-routers-ship-with.html\">20 Zbtlink router models.<\/p>\n<p>VulnCheck&#8217;s advisory for <a href=\"https:\/\/www.vulncheck.com\/advisories\/zbtlink-mqwrt-infosrvd-command-injection\">the DARKLANTERN command injection<\/a> and its advisory for <a href=\"https:\/\/www.vulncheck.com\/advisories\/zbtlink-mqwrt-yunmgrd-cloud-c2-implant\">the SPEAKINGSTONE C2 implant<\/a> name the following models and firmware builds &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-74233 (DARKLANTERN)<\/strong> &#8211; Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108 and WG3526 on firmware 19.1101, WE2426-C on 19.1112, WE5926-EC_QP on 20.0516 and WF3526-P on 19.051, plus CTN720-W1, LF-1541 and MT7620N on 19.1101 and WRC1 on 20.0622, which the CVE record lists under an unidentified vendor.<\/li>\n<li><strong>CVE-2026-74232 (SPEAKINGSTONE)<\/strong> &#8211; Zbtlink L3_V2_8 on 3.0.0.4.528, WE826-T2 on 19.1101, ZBT-7628 on 1.0.0.2.007 and ZBT-ZBT7621 on 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A and MQAP-7628 on 1.0.0.2.000, and AP522 on 1.0.0.2.014, AP7628 and HC5661A on 3.0.0.4.380, APG721B on 19.0809, HK300 on 1.0.0.2.032 and MAP-N10 on 1.0.0.2.044 under an unidentified vendor.<\/li>\n<\/ul>\n<p>The advisory pages display those builds as upper bounds, while the CVE records name each firmware as a single exact build and set the default status of every other version to unknown. Neither advisory names a fixed firmware release, leaving an owner on a build outside the listed set without a published basis for deciding whether the flaw applies.<\/p>\n<p>Model number rather than brand is the reliable check, because ZBT sells the same hardware and firmware to resellers that put their own name on the case. The Hacker News confirmed via the IEEE-registered MAC prefix database on August 28 that the blocks 78:A3:51 and F8:5E:3C are both assigned to Shenzhen Zhibotong Electronics, letting an owner identify the manufacturer from the device&#8217;s own address.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJpr-Ua5OEVw1C51WgcvQ3DPtimxeVUHxr4CTHqhI_6hLxVcU-yzWd3jAzkTw8FLSU-mgSV2XUSDwln-VdICbtGKYQy4VNOn_3ALR3mmXsa6W4Rj95rr8qwtSidmUnJco8TJvFehrNrpDK1R7EWHK3rKUCrOJCHSHcFVr4HNEwLTdhqd7A_8HO6snLC70\/s1700-e365\/exe.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJpr-Ua5OEVw1C51WgcvQ3DPtimxeVUHxr4CTHqhI_6hLxVcU-yzWd3jAzkTw8FLSU-mgSV2XUSDwln-VdICbtGKYQy4VNOn_3ALR3mmXsa6W4Rj95rr8qwtSidmUnJco8TJvFehrNrpDK1R7EWHK3rKUCrOJCHSHcFVr4HNEwLTdhqd7A_8HO6snLC70\/s1700-e365\/exe.png\" alt=\"\" border=\"0\" data-original-height=\"941\" data-original-width=\"1672\"\/><\/a><\/div>\n<p>SPEAKINGSTONE carries a hardcoded backup C2 domain that the implant reaches for where a primary server was never configured, and VulnCheck found that domain unregistered.<\/p>\n<p>The company registered the domain and stood up a server running a reverse-engineered implementation of the protocol. Beacons began arriving as soon as the server was live.<\/p>\n<p>As of August 21, 392 unique devices had reported in, of which 390 were in China. VulnCheck said 83 percent were on China Mobile&#8217;s network, that 304 of the 392 broadcast SSIDs beginning with \u00abCMCC\u00bb, and that 363 self-reported a single model, L3_V2_8, running firmware 3.0.0.4.528.<\/p>\n<p>Because a device reaches the backup domain only where a primary C2 was never configured, the 392 are a floor drawn from an unrepresentative subset rather than a count of affected devices.<\/p>\n<p>VulnCheck flags CVE-2026-74233 in its own Known Exploited Vulnerabilities catalog, whose published criteria require that a vulnerability be \u00abpublicly-reported as exploited in the wild.\u00bb<\/p>\n<p>CISA&#8217;s Vulnrichment enrichment, recorded against the same CVE on August 27, rates exploitation as proof of concept, which the agency&#8217;s documentation defines as a public proof-of-concept existing at the time of analysis. The Hacker News confirmed via <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CISA&#8217;s Known Exploited Vulnerabilities catalog<\/a>, version 2026.08.27, that none of the three ZBT CVEs appear in it as of August 28.<\/p>\n<p>VulnCheck published the following indicators of compromise (IoCs) &#8211;<\/p>\n<ul>\n<li><strong>Domains<\/strong> &#8211; <code>www.ac-link[.]com<\/code>, the SPEAKINGSTONE primary C2, and <code>www.findmyipaddr[.]com<\/code>, the backup domain VulnCheck registered<\/li>\n<li><strong>IP address<\/strong> &#8211; <code>47.107.224[.]89<\/code>, an Alibaba Cloud address in Shenzhen that the primary C2 domain still resolved to when The Hacker News checked on August 28<\/li>\n<li><strong>Ports<\/strong> &#8211; UDP\/9992 inbound for DARKLANTERN, UDP\/8897 for its responses, and UDP\/10000 outbound for SPEAKINGSTONE beacons<\/li>\n<li><strong>Services and paths<\/strong> &#8211; <code>infosrvd<\/code>, <code>yunmgrd<\/code>, <code>inetdetect<\/code>, <code>\/etc\/exec\/cmd<\/code>, <code>\/tmp\/info.txt<\/code> and <code>\/tmp\/yunclient.conf<\/code><\/li>\n<li><strong>SHA-256 hashes<\/strong> &#8211; <code>b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818<\/code> (yunmgrd), <code>7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245<\/code> (infosrvd) and <code>ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926<\/code> (inetdetect)<\/li>\n<\/ul>\n<p>VulnCheck&#8217;s guidance for the earlier implant was to block and alert on the endpoints at both the egress and the resolver, and to treat the router&#8217;s LAN as untrusted.<\/p>\n<p>Because DARKLANTERN listens on UDP\/9992, blocking inbound traffic to that port at the network edge closes off the listener while a fixed release is outstanding.<\/p>\n<p>VulnCheck published Suricata and YARA rules alongside the research, one of which alerts on DARKLANTERN command output arriving on UDP port 8898 while the accompanying text and scanner both use 8897.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Zbtlink addressed the earlier ENDLESSDOORS component in <a href=\"https:\/\/www.zbtlink.com\/pages\/zbt-router-firmware-download-announcement\">a statement on its website<\/a>, saying it serves solely as an after-sales technical support tool used only on a customer&#8217;s explicit request and authorization.<\/p>\n<p>\u00abThis component has never been used for unauthorized access,\u00bb the company said.<\/p>\n<p>A Zbtlink spokesperson told The Hacker News on August 6 that the feature is \u00absolely intended\u00bb for after-sales maintenance and serves no other purposes.<\/p>\n<p>\u00abIt is generally retained only on sample units to assist customers with software debugging,\u00bb the spokesperson added.<\/p>\n<p>That statement addresses ENDLESSDOORS alone, and Zbtlink has issued no public statement on <code>yunmgrd<\/code> or <code>infosrvd<\/code>.<\/p>\n<p>The Hacker News found on August 28 that the company&#8217;s firmware download pages were live and serving eight images dated August 17, among them builds for the WE826-T2 and WE2426-C, both named in the new advisories.<\/p>\n<p>VulnCheck said the implants ship with ZBT firmware, and pointed to MOFI Network, which develops its own firmware for the same platform and whose examined image was free of the three implants.<\/p>\n<p>The Hacker News has reached out to Zbtlink for comment on whether its current firmware still contains the two components, and to VulnCheck for the evidence behind its catalog listing, and will update this story with any response.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2593,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,622,3218,3220,502,61,873,2910,725,3219],"class_list":["post-2592","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-attackers","tag-chinamade","tag-giving","tag-implants","tag-root","tag-routers","tag-ship","tag-unauthenticated","tag-zbt"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2592","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2592"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2592\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2593"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2592"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2592"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2592"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}