Image: VulnCheck
TL;DR
VulnCheck found firmware-level implants in ZBT routers sold worldwide, including on Amazon. The ZBT router backdoor grants an unauthenticated attacker root access over the internet. Researchers track the flaws as CVE-2026-74232 and CVE-2026-74233, both rated CVSS 9.3.
- Product: Zbtlink (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-74232, CVE-2026-74233)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: MQWrt yunmgrd Cloud C2 Implant
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-74232 | 9.8 | MQWrt yunmgrd Cloud C2 Implant | — | Not exploited |
| CVE-2026-74233 | 9.8 | MQWrt infosrvd Command Injection | — | Not exploited |
Why It Matters
ZBT is Shenzhen Zhibotong Electronics. It rarely sells under its own name. Instead, it builds hardware that other brands relabel. VulnCheck tied ZBT gear to sellers across the United States, Canada, Australia, the Philippines, Germany, and Russia. One tested unit was an $88 Deep Orange router bought on Amazon from a New York company. As the report warns, “just because you’ve never heard of Shenzhen Zhibotong Electronics or the ZBT-WE826 doesn’t mean you haven’t interacted with one.” That reach turns a single ZBT router backdoor into a broad supply chain risk.
How the Attack Works
The team found two new implants after its earlier ENDLESSDOORS research. Both surfaced on a white-labeled ZBT-WE826-T2.
DARKLANTERN
DARKLANTERN is a WAN listener. It runs as infosrvd on UDP port 9992. The router’s default firewall allows inbound traffic to that port from anywhere. Its protocol is “simple, unauthenticated, and unencrypted.” A command packet passes a shell string straight to the system, yielding a root shell. Two checks gate the packet, a token and a MAC address. Both fail by design. The token uses a hardcoded salt. The MAC filter contains an all-zero bypass. VulnCheck put it plainly: “One packet for a root shell over the internet.”
SPEAKINGSTONE
SPEAKINGSTONE takes the opposite approach. It beacons outward as yunmgrd over UDP port 10000. This design works behind NAT and firewalls, because the device dials home on its own. The C2 replies with commands. No exploit code appears here.
What the Implant Can Do
SPEAKINGSTONE is the more capable ZBT router backdoor. It can run arbitrary commands, steal PPPoE ISP credentials, hijack DNS, and open reverse SSH tunnels. Inbound commands stay in plaintext. As VulnCheck notes, “Anyone on the network path can hijack these implants.” The report calls it “a surveillance implant with root access to every device it runs on.”
Affected Versions
CVE-2026-74232 covers the SPEAKINGSTONE implant across models like the ZBT L3_V2_8, WE826-T2, ZBT-7628, and several MoreQuick units. CVE-2026-74233 covers the DARKLANTERN command injection across ZBT models such as WE1326, WE2426-C, WE826-WD, and WG3526. VulnCheck stresses these are older devices. Firmware on its test unit dated to 2019. The installed base was “almost certainly larger.”
Exploitation Status
VulnCheck confirmed live deployments through its own scanning. Between August 18 and 21, 2026, it found 203 internet-facing DARKLANTERN instances across 22 countries. The United States led with 103. The team also sinkholed a forgotten backup domain, findmyipaddr[.]com, which the vendor left unregistered. Hundreds of devices reported in. As of August 21, 392 unique devices had beaconed to the sinkhole, and 390 sat in China on carrier networks. Researchers report no separate criminal campaign abusing these bugs yet, but the primary C2, ac-link[.]com, remains live.
Patch and Mitigation
No vendor fix is confirmed. ZBT earlier called such code an “after-sales technical support tool,” a claim VulnCheck disputes. Treat affected routers as compromised. Remove ZBT-based devices from sensitive networks. Block inbound UDP to ports 9992 and 10000. Restrict outbound traffic to unknown hosts. Where possible, replace the hardware. As VulnCheck concludes, “These devices do not belong on American networks.”
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!