
highVulnerability
Undocumented Factory Implants Discovered in Shenzhen Zhibotong ZBT Routers
VulnCheck researchers have disclosed two previously undocumented factory implants embedded in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Tracked as CVE-2026-74232 and CVE-2026-74233, the implants SPEAKINGSTONE and DARKLANTERN allegedly allow unauthenticated remote attackers to execute commands as root on affected devices. The findings, reported by The Hacker News, indicate the implants have been present in shipped devices since manufacture. No official patch has been mentioned, and the CVE assignments are subject to verification through official CNA processes.
The Hacker News2 min read