China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
PoC publicZBT RoutersOur summary
VulnCheck has identified two undocumented backdoors in Shenzhen Zhibotong Electronics (ZBT) router firmware that allow remote attackers to execute commands with root privileges without authentication. These vulnerabilities, tracked as CVE-2026-74232 and CVE-2026-74233, enable full device control through hardcoded services named SPEAKINGSTONE and DARKLANTERN.
Affected models include various Zbtlink devices such as the WE826-T2 and WG108, depending on specific firmware versions like 19.1101. Since no fixed release has been announced, users are advised to block inbound UDP port 9992 and outbound UDP port 10000 at the network edge to mitigate exposure.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.