CVE Tools

В роутерах ZBT обнаружили еще два бэкдора

Хакер (xakep.ru)By Мария Нефёдова

PoC publicZBT WE826-T2Deep Orange 3G/4G/LTE Router

Our summary

Security firm VulnCheck has identified two previously unknown root-level implants, dubbed SPEAKINGSTONE and DARKLANTERN, within the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These vulnerabilities, assigned CVE-2026-74232 and CVE-2026-74233, allow remote attackers to execute arbitrary commands without authentication, earning them high severity scores of 9.8 on CVSS 3.1.

SPEAKINGSTONE operates as a persistent service that exfiltrates data over UDP port 10000, enabling actions such as PPPoE credential theft and reverse SSH tunneling, while DARKLANTERN exposes a vulnerable command interface on UDP port 9992 where security checks can be easily bypassed. The discovery follows a similar finding in July regarding the ENDLESSDOORS implant, reinforcing concerns about the inherent risks in ZBT's OEM business model where identical hardware is sold under multiple brands.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store