Summary
- Security firm VulnCheck discovered two previously unknown implants, dubbed SPEAKINGSTONE and DARKLANTERN, in firmware shipped on ZBT-brand routers made by Shenzhen Zhibotong Electronics.
- Both implants are factory-installed, meaning they are present out of the box, before any user configuration or deployment.
- Either implant gives an unauthenticated remote attacker the ability to execute arbitrary commands with root privileges on affected devices.
- The vulnerabilities are tracked as CVE-2026-74232 (SPEAKINGSTONE) and CVE-2026-74233 (DARKLANTERN).
- No corroborating sources or vendor response details are available at this stage beyond VulnCheck’s disclosure.
What was found
VulnCheck’s zero-day research team has disclosed two factory-installed implants hidden within the firmware of routers manufactured by Shenzhen Zhibotong Electronics, a Chinese hardware vendor operating under the ZBT brand. The implants, which the researchers named SPEAKINGSTONE and DARKLANTERN, were not documented by the manufacturer and had not been previously reported. Both have now been assigned CVE identifiers: CVE-2026-74232 for SPEAKINGSTONE and CVE-2026-74233 for DARKLANTERN.
The nature of the risk
The critical detail here is that neither implant requires an attacker to have valid credentials. An unauthenticated remote attacker exploiting either vulnerability can execute commands on the affected device with root-level privileges — effectively full control of the hardware. Because the implants are present in the factory firmware, every device shipped with that firmware is affected from the moment it is powered on, regardless of how it is subsequently configured by the end user or IT team.
Factory-level compromise raises supply chain questions
The presence of implants at the firmware level, embedded before devices reach customers, shifts this beyond a conventional software vulnerability. It raises questions about the integrity of the supply chain for these devices and whether the implants were introduced deliberately or as a consequence of a compromised build process. VulnCheck’s disclosure does not, based on the available source material, attribute the implants to any specific threat actor or state-sponsored group, and the source material does not include any statement from Shenzhen Zhibotong Electronics.
What is not yet known
At the time of writing, the available source material does not specify which ZBT router models or firmware versions are confirmed affected, whether a patch or firmware update has been issued, or whether the vendor has acknowledged the findings. It is also not known from the available material how widely these devices are deployed in enterprise or government environments, nor whether VulnCheck has observed active exploitation in the wild. These are material gaps for organisations conducting immediate risk assessments.
Context: routers as a persistent target
Network edge devices — routers in particular — have been a sustained focus for sophisticated threat actors because they sit at the perimeter of an organisation’s environment, often run for extended periods without updates, and are not always covered by endpoint detection tooling. A device that ships with a root-access backdoor already in place effectively renders all other perimeter controls secondary. For security teams, the challenge with firmware-level implants is that they can survive reboots and even some factory reset procedures, depending on how they are implemented.
Why it matters
For CISOs, the significance of this disclosure is less about a single vendor’s product and more about what it illustrates: that hardware entering the network may carry security exposures that predate deployment and that no amount of configuration hardening will remediate. If ZBT routers are present in your environment — particularly in branch offices, OT networks, or any segment where procurement decisions are made outside central IT governance — those devices should be treated as potentially compromised pending further investigation. More broadly, this is a prompt to review hardware procurement policies, ensure router firmware provenance can be verified, and confirm that network monitoring would detect anomalous outbound traffic or lateral movement originating from edge devices.
What to do now
- Audit your environment for any routers manufactured by Shenzhen Zhibotong Electronics (ZBT brand) and document their locations and network roles.
- Monitor VulnCheck’s disclosure and the relevant CVE entries (CVE-2026-74232 and CVE-2026-74233) for updates on affected models, firmware versions, and any available patches.
- Until further guidance is available, consider isolating affected devices or restricting remote management access to these routers as a precautionary measure.
- Review procurement and supply chain policies to ensure hardware firmware integrity can be validated before devices are deployed in production environments.
- Confirm that network monitoring tools are positioned to detect unusual traffic patterns or command-and-control activity originating from edge network devices.
