#8
The Hacker News
general
August 28, 2026 at 10:58 UTC
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
By [email protected] (The Hacker News)
AI Summary
VulnCheck disclosed two factory-installed implants, SPEAKINGSTONE (CVE-2026-74232) and DARKLANTERN (CVE-2026-74233), embedded in firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT), both granting unauthenticated remote attackers root-level command execution. One implant is reachable over the network while the other exploits Bluetooth Low Energy to target the router's Locomotion PC. The supply-chain nature of these implants, present from factory, makes detection difficult and affects all devices shipped with the vulnerable firmware.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →