By Interestana AI Editorial — AI-drafted, human-overseen. How we report
China-Made ZBT Routers Ship With Two Implants Giving Attackers Root Access

VulnCheck has disclosed the presence of two undocumented factory implants embedded within the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These implants grant unauthenticated remote attackers the ability to execute commands with root privileges on affected devices. The zero-day research team at VulnCheck has named these implants SPEAKINGSTONE and DARKLANTERN. They are officially tracked under the Common Vulnerabilities and Exposures (CVE) identifiers CVE-2026-74232 and CVE-2026-74233, respectively. The discovery highlights significant security vulnerabilities originating from the manufacturing process itself, bypassing typical software update and patching mechanisms.
Shenzhen Zhibotong Electronics (ZBT) is a company based in China that specializes in the production of networking equipment, including routers. The routers in question are designed for various networking applications, and the presence of these implants suggests a potential for widespread compromise if these devices are deployed in sensitive environments. The implants are described as "factory implants," indicating they were likely pre-installed during the manufacturing stage, making them exceptionally difficult to detect and remove through standard security practices. This contrasts with typical vulnerabilities that are introduced through software bugs or misconfigurations that can be addressed via firmware updates.
The research conducted by VulnCheck, a cybersecurity firm known for its focus on zero-day vulnerabilities, involved a deep analysis of the firmware. The implants are designed to provide attackers with a persistent and privileged level of access. This level of access allows for a wide range of malicious activities, including the installation of further malware, data exfiltration, network reconnaissance, and the use of the compromised device as a pivot point to attack other systems within a network. The fact that these implants are present from the factory means that even brand-new, unconfigured devices are potentially compromised out of the box, posing an immediate threat to users and organizations upon deployment.
The implications of this discovery are substantial for network security. Devices with such deep-seated vulnerabilities can undermine the security posture of entire networks. Organizations that have deployed ZBT routers, or similar devices from manufacturers with questionable supply chain security, are at risk. The research team's identification of these specific CVEs allows for better tracking and potential mitigation efforts, although the nature of factory implants makes patching extremely challenging. Users are advised to investigate the origin and firmware integrity of their networking devices, particularly those manufactured by less scrutinized vendors, and to consult security advisories from researchers like VulnCheck for detailed technical information and potential workarounds or indicators of compromise.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.