Affected users should contact Zhibotong Electronics for firmware updates, implement network segmentation, and monitor for anomalous router behavior. Verify CVE assignments through official CNA processes. No official patch has been released as of disclosure.
Quick answers
What is CVE-2026-74233?
Affected users should contact Zhibotong Electronics for firmware updates, implement network segmentation, and monitor for anomalous router behavior. Verify CVE assignments through official CNA processes. No official patch has been released as of disclosure.
How severe is CVE-2026-74233?
high
Is CVE-2026-74233 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-74233 be mitigated?
Affected users should contact Zhibotong Electronics for firmware updates, implement network segmentation, and monitor for anomalous router behavior. Verify CVE assignments through official CNA processes. No official patch has been released as of disclosure.
CVSS
—
Vendor
Shenzhen Zhibotong Electronics
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
ZBT routers
Mitigation
Affected users should contact Zhibotong Electronics for firmware updates, implement network segmentation, and monitor for anomalous router behavior. Verify CVE assignments through official CNA processes. No official patch has been released as of disclosure.
VulnCheck researchers have disclosed two previously undocumented factory implants embedded in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Tracked as CVE-2026-74232 and CVE-2026-74233, the implants SPEAKINGSTONE and DARKLANTERN allegedly allow unauthenticated remote attackers to execute commands as root on affected devices. The findings, reported by The Hacker News, indicate the implants have been present in shipped devices since manufacture. No official patch has been mentioned, and the CVE assignments are subject to verification through official CNA processes.