В роутерах ZBT обнаружили еще два бэкдора
PoC publicZBT WE826-T2Deep Orange 3G/4G/LTE RouterOur summary
Security firm VulnCheck has identified two previously unknown root-level implants, dubbed SPEAKINGSTONE and DARKLANTERN, within the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These vulnerabilities, assigned CVE-2026-74232 and CVE-2026-74233, allow remote attackers to execute arbitrary commands without authentication, earning them high severity scores of 9.8 on CVSS 3.1.
SPEAKINGSTONE operates as a persistent service that exfiltrates data over UDP port 10000, enabling actions such as PPPoE credential theft and reverse SSH tunneling, while DARKLANTERN exposes a vulnerable command interface on UDP port 9992 where security checks can be easily bypassed. The discovery follows a similar finding in July regarding the ENDLESSDOORS implant, reinforcing concerns about the inherent risks in ZBT's OEM business model where identical hardware is sold under multiple brands.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.