The record
Written from the 1 report below. Nothing here is unsourced.
- Security firm VulnCheck has disclosed two factory implants, SPEAKINGSTONE and DARKLANTERN, embedded in firmware for routers made by Shenzhen Zhibotong Electronics (ZBT), tracked as CVE-2026-74232 and CVE-2026-74233 and rated 9.8 on CVSS 3.1.
- The implants allow an unauthenticated remote attacker to run commands as root, with SPEAKINGSTONE dialing out to a command-and-control server and DARKLANTERN accepting inbound connections on an internet-exposed UDP port.
- VulnCheck found 203 internet-facing DARKLANTERN instances across 22 countries and, after registering a dormant backup C2 domain, received beacons from 392 devices, nearly all in China.
- No fixed firmware releases are named, and because ZBT sells white-labeled hardware to resellers, owners are advised to check model numbers and the manufacturer's MAC prefixes to determine exposure.
What to watch next
- Whether CISA adds the ZBT CVEs to its Known Exploited Vulnerabilities catalog, since VulnCheck has flagged CVE-2026-74233 as exploited in the wild.
- Whether any vendor publishes fixed firmware releases, given the advisories name no patched builds and leave other versions' status unknown.
- Growth in beacon counts or new affected models as VulnCheck's sinkholed backup C2 domain continues collecting reports.
Coverage1
1 report
English national1
All filed from India
Named China · United States · Shenzhen Zhibotong Electronics · ZBT · Zbtlink · MOFI Network · VulnCheck
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
