Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
VulnCheck disclosed on August 27, 2026 two factory firmware implants present in routers from Shenzhen Zhibotong Electronics (ZBT): SPEAKINGSTONE and DARKLANTERN. Both allow unauthenticated remote command execution as root. The affected models are resold under dozens of different brands, including consumer channels such as Amazon. As of August 28, no firmware update removing the two services has been confirmed.
- Two implants — SPEAKINGSTONE (CVE-2026-74232) and DARKLANTERN (CVE-2026-74233) — are embedded in ZBT production router firmware.
- Both score CVSS 9.8 out of 10 in version 3.1: network attack vector, no privileges required, no user interaction needed.
- 392 devices contacted a SPEAKINGSTONE backup domain controlled by VulnCheck, 390 in China; 203 DARKLANTERN instances are exposed on the internet across 22 countries.
- Zbtlink has issued no public communications regarding
yunmgrdorinfosrvd, and its download pages serve firmware dated August 17, 2026.
The Two Hidden Services: yunmgrd and infosrvd
SPEAKINGSTONE operates as the yunmgrd service and establishes beacons to a hardcoded command-and-control server, www.ac-link.com, which VulnCheck research shows resolves to an Alibaba Cloud IP address in Shenzhen. The protocol supports arbitrary root command execution, PPPoE credential exfiltration, reading and writing DNS hijack lists, and opening reverse SSH tunnels. A backup domain, www.findmyipaddr.com, is hardcoded in the binary; VulnCheck registered the domain and operated a sinkhole.
DARKLANTERN runs as infosrvd on UDP/9992, with the port open to the internet by the stock firewall. The authentication mechanism is ineffective: it combines a hardcoded salt with a zeroed wildcard MAC value that bypasses the address check. This allows anyone to send commands with root privileges.
A Deep Orange 3G/4G/LTE router purchased from a U.S. vendor for $88, labeled ZBT-WE826-T2 with 2019 firmware, revealed both implants upon analysis.
"This is a surveillance implant with root access to every device it runs on"
— VulnCheck supply chain research
Field Data: 392 Beacons, 203 Exposed Instances
The sinkhole operation on www.findmyipaddr.com recorded 392 unique devices through August 21, of which 390 were in China and 83% on the China Mobile network. Three hundred four report SSIDs with the 'CMCC' prefix, the operator's consumer brand. These numbers represent a floor, however: as VulnCheck notes, devices reach the backup domain only when the primary C2 has never been configured, so the sample is non-representative.
For DARKLANTERN, internet scanning from August 18–21 detected 203 reachable instances across 22 countries, with 16 distinct self-reported models in probes. The geographic distribution extends beyond China, indicating an international sales network.
MAC prefixes 78:A3:51 and F8:5E:3C, assigned to Shenzhen Zhibotong Electronics by the IEEE, are the most reliable indicator of hardware provenance. ZBT sells the same hardware and firmware to resellers for rebranding: the model number, not the brand on the case, is the only verifiable criterion.
The "Debug Tool" Defense and the ENDLESSDOORS Precedent
SPEAKINGSTONE and DARKLANTERN are the third and fourth public cases of ZBT firmware implants in 2026. In June, VulnCheck disclosed ENDLESSDOORS (CVE-2026-66747), another hidden service with unauthenticated root access. The pattern is clear: each cycle reveals a system service with hardcoded Chinese infrastructure, absent or broken authentication, and root execution.
Zbtlink has issued public statements only for ENDLESSDOORS, not for the two new implants. The recurring justification — a diagnostic tool accidentally left in production — collides with the reality of hardcoded C2, predetermined salts, and systematic security bypasses. The distinction between human error and intentional design remains unproven, but the density of functional elements oriented toward remote control renders the first hypothesis semantically insufficient.
MOFI Network, an independent firmware developer for the same hardware platform, has confirmed its distribution lacks all three known implants. This demonstrates the services are not intrinsic to the underlying MediaTek platform.
The Regulatory Gap at the Network Edge
The affected routers sit at the boundary between consumer and small-business infrastructure: inexpensive, often white-label devices purchasable on transnational marketplaces with obscured manufacturing identity. The OEM/ODM model, in which a single Chinese manufacturer serves dozens of brands, nullifies asset inventory and risk assessment.
The operational consequences are concrete. Both implants bypass NAT: SPEAKINGSTONE via outbound connection to C2, DARKLANTERN via a directly exposed inbound port. Neither requires authentication. Neither requires user interaction. Both achieve maximum privileges. This profile matches CISA KEV catalog criteria, yet as of August 28 neither CVE-2026-74232 nor CVE-2026-74233 appeared in the catalog. VulnCheck has added CVE-2026-74233 to its internal KEV catalog; CISA Vulnrichment assesses exploitation status as "proof-of-concept."
The risk of lateral movement and persistent access is implicit in the technical profile, but the dossier documents no in-the-wild exploitation beyond VulnCheck's research and operational sinkhole.
Why It Matters
The brief documents no specific remedial measures released by Zbtlink. Firmware download pages were active on August 28 and served images dated August 17, including models WE826-T2 and WE2426-C, but the state of those binaries — whether cleaned or not — is not verified by the primary source. No firmware version is indicated as corrective in the CVE advisories.
The source does not specify the nature of data exposed on the 392 sinkholed devices beyond the PPPoE credentials and network parameters transmitted in the beacon. It does not identify who inserted the implants, under what mandate, or whether the same infrastructure serves other operators. The dossier does not clarify whether CISA intends to add the two vulnerabilities to the official KEV catalog.
For buyers, identifying ZBT hardware relies exclusively on IEEE MAC prefixes or the model number printed on the device; brands on the case are interchangeable. MOFI Network offers a verified alternative firmware, but flashing requires technical skills beyond the average user.
The case raises supply-chain governance questions that current frameworks do not cover: a network device manufactured in China, resold in the West under unknown brands, can contain preinstalled remote-control code without mandatory disclosure, patch, or recall mechanisms. The absence of these mechanisms is a fact, not a hypothesis.
Questions and Answers
How do I know if my router is affected?
Check the model number printed on the device, not the brand on the case. MAC prefixes 78:A3:51 or F8:5E:3C indicate ZBT hardware. The presence of active yunmgrd or infosrvd services confirms infection, but requires shell access to the router.
Why isn't 392 devices the total?
The domain www.findmyipaddr.com is a backup contacted only when the primary C2 is not configured. The 392 devices therefore represent a non-representative subset: those never properly configured, or with a failed primary C2.
What distinguishes this from a normal firmware vulnerability?
The systematic recurrence: four distinct implants in a few months, each with unauthenticated root, each with hardcoded Chinese infrastructure. MOFI Network has demonstrated the same hardware platform can operate without these services, ruling out the explanation that they are necessary for system function.
Sources
- https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
- https://www.helpnetsecurity.com/2026/08/27/fbi-disrupts-china-linked-hacking-network/
- https://thomasharris6.wordpress.com/2026/08/28/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/
- https://www.systemtek.co.uk/2026/08/chinese-made-zbt-routers-found-containing-two-hidden-backdoors/
- https://www.thehackerwire.com/zbtlink-firmware-unauthenticated-root-command-injection-udp-9992/
- https://startupfortune.com/zbtlink-routers-on-amazon-hide-a-backdoor-that-phones-china-every-35-seconds/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
- https://thehackernews.uk/corelight-d
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.