Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageOT/IoT Security Desk
OT/IoT Security

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck reveals two factory-installed backdoors—SPEAKINGSTONE and DARKLANTE—in ZBT router firmware granting unauthenticated root access, raising serious hardware supply-chain concerns for European network operators.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readCVE-2026-74232Read at source ↗
CVSS9.8criticalCVE-2026-74232+1 more

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.

The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Editorial Analysis

Why it matters

Factory-implanted backdoors in networking equipment undermine every downstream security control and call into question hardware procurement practices across European supply chains.

What to do

Identify any ZBT-manufactured or white-label routers in your infrastructure, isolate affected devices, and begin hardware replacement planning.

Board brief

Routers from a Chinese manufacturer ship with pre-installed backdoors—a hardware supply-chain risk that demands immediate procurement review.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the OT/IoT Security Desk