Two previously undocumented factory implants have been discovered in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT), each allowing an unauthenticated remote attacker to execute commands with root privileges on affected devices. VulnCheck disclosed the implants, named SPEAKINGSTONE and DARKLANTERN, on August 28, 2026, assigning them CVE identifiers CVE-2026-74232 and CVE-2026-74233 with severity ratings of 9.3 on the CVSS 4.0 scale and 9.8 on CVSS 3.1. Both vulnerabilities enable network attacks that require no privileges and no user interaction.
SPEAKINGSTONE operates as a service called yunmgrd, transmitting beacons over UDP port 10,000 to a hardcoded command-and-control server. The implant functions from behind network address translation and standard egress filtering because it initiates outbound connections. Its protocol handles message types that run arbitrary commands as root, steal WAN PPPoE credentials, manipulate a DNS hijack list, and establish a reverse SSH tunnel. DARKLANTERN runs as the service infosrvd on UDP port 9992, which the router's default firewall leaves open to inbound connections from any internet address. Between August 18 and August 21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries, reporting 16 distinct models. VulnCheck registered an unoccupied backup domain hardcoded into SPEAKINGSTONE and stood up a server running a reverse-engineered version of the protocol. As of August 21, 392 unique devices had sent beacons, of which 390 were located in China, with 83 percent on China Mobile's network and 304 broadcasting SSIDs beginning with "CMCC."
"This is a surveillance implant with root access to every device it runs on," VulnCheck said in its supply chain research. The advisory describes DARKLANTERN's authentication as ineffective, relying on a hardcoded salt and an all-zero wildcard MAC value that circumvents its own address verification. Both implants were found on an $88 Deep Orange 3G/4G/LTE Router purchased from a U.S. supplier, a white-labeled ZBT-WE826-T2 with firmware built in 2019. CVE-2026-74233 affects Zbtlink models WE1326, WE357, WE5926, WE826-Q, WE826-T2, WG108, and others on firmware 19.1101, while CVE-2026-74232 impacts Zbtlink L3_V2_8 on 3.0.0.4.528, WE826-T2 on 19.1101, and multiple MoreQuick models on 1.0.0.2.000, among others. Neither advisory identifies a patched firmware release, leaving owners on unlisted builds without published guidance on whether the vulnerability applies.
The implants ship with ZBT firmware, VulnCheck said, pointing to MOFI Network, which develops its own firmware for the same hardware platform and whose examined image contained none of the three implants. Because ZBT sells identical hardware and firmware to resellers who rebrand the products, model number rather than brand name provides the reliable check. VulnCheck's guidance for SPEAKINGSTONE was to block and alert on the endpoints at both the egress and the resolver and to treat the router's LAN as untrusted. For DARKLANTERN, blocking inbound traffic to UDP port 9992 at the network edge closes the listener while a fix remains outstanding. Zbtlink addressed the earlier ENDLESSDOORS implant in a website statement, calling it solely an after-sales technical support tool used only with customer authorization, but the company has issued no public statement on yunmgrd or infosrvd. The Hacker News found on August 28 that Zbtlink's firmware download pages were live and serving eight images dated August 17, including builds for the WE826-T2 and WE2426-C, both named in the new advisories. The degree to which after-sales access justifies preinstalled backdoor mechanisms will likely hinge on whether manufacturers treat remote access as an opt-in service or a default feature, and whether device owners maintain meaningful oversight of when and how such tools activate.

