ZBT Routers Found With Two Hidden Factory Backdoors Handing Attackers Full Control
Researchers at VulnCheck say firmware shipped by Shenzhen Zhibotong Electronics contains two undocumented implants that let anyone on the internet run commands as root.

Key points
- VulnCheck disclosed two undocumented implants baked into the factory firmware of routers made by Shenzhen Zhibotong Electronics (ZBT).
- The implants are named SPEAKINGSTONE and DARKLANTERN, tracked as CVE-2026-74232 and CVE-2026-74233.
- Both let an unauthenticated attacker run any command as root, meaning full control of the router without a password.
- The implants sit inside the firmware as it ships from the factory, not something added by a hacker after the fact.
- ZBT sells small business and industrial routers, including 4G and 5G models resold under other brand names worldwide.
Two hidden doorways were built into routers from Chinese manufacturer Shenzhen Zhibotong Electronics, better known as ZBT, and either one lets a stranger on the internet take the device over completely.
The finding comes from VulnCheck's zero-day research team, and was first detailed by The Hacker News. VulnCheck's researchers call the implants SPEAKINGSTONE and DARKLANTERN. In vulnerability tracking terms they are CVE-2026-74232 and CVE-2026-74233.
An implant, in this context, is code that sits inside the device's firmware, the built-in software that runs the router, and quietly gives an outsider a way in. Because these were found in firmware straight from the factory, they were not planted by a later hack. They were there when the box was opened.
What can an attacker actually do?
Run anything they want on the router, as the top-level administrator, without needing a username or password. That is what "unauthenticated remote code execution as root" means in plain English.
Once inside, an attacker can read the traffic passing through the router, redirect users to fake websites, install more malicious software, or use the router as a launchpad to attack other machines on the same network. For a small business, that is every email, every payment, every login potentially visible to someone else.
Who makes ZBT routers, and where do they turn up?
ZBT is a Shenzhen-based hardware maker that produces Wi-Fi routers, 4G and 5G cellular routers, and industrial networking gear. Its devices are sold directly and also rebadged by other vendors, which means the same firmware, and the same implants, can appear under a name that is not ZBT at all.
That resale pattern is the awkward part. A buyer may not know their router is a ZBT device underneath. Owners of small business routers, kiosks, vending equipment and industrial sensors that rely on cellular routers should check the maker of the internal board, not just the sticker on the case.
The two implants at a glance
| Implant name | CVE ID | What it gives the attacker |
|---|---|---|
| SPEAKINGSTONE | CVE-2026-74232 | Unauthenticated remote command execution as root |
| DARKLANTERN | CVE-2026-74233 | Unauthenticated remote command execution as root |
What should owners of ZBT routers do now?
Assume the device is exposed until you hear otherwise from the vendor. There is no vendor patch confirmed in the disclosure, and factory-level implants cannot be fixed by changing a password or updating a setting inside the web interface.
Practical steps for anyone who suspects they own an affected device:
- Take the router off any public-facing internet connection where possible, or put it behind a separate firewall.
- Turn off remote management features so the router's admin page is not reachable from the internet.
- Ask the reseller or supplier whether the hardware is built on a ZBT board, and whether firmware from a different, trusted source is available.
- Watch for unusual outbound traffic from the network the router serves, which can hint the device is being used by someone else.
Regulators have not yet weighed in publicly. In the United States the Federal Trade Commission has previously acted against router vendors that shipped insecure devices, and the Cybersecurity and Infrastructure Security Agency tracks known-exploited flaws that federal agencies must fix. Both are worth watching as this disclosure develops.



