← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 28, 2026 · 10:58via The Hacker News

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Brief

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.

The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Read more on The Hacker News