Home / Aug 29, 2026 / Story
0
#8 The Hacker News general August 28, 2026 at 10:58 UTC

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

By [email protected] (The Hacker News)

AI Summary

VulnCheck disclosed two factory-installed implants, SPEAKINGSTONE (CVE-2026-74232) and DARKLANTERN (CVE-2026-74233), embedded in firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT), both granting unauthenticated remote attackers root-level command execution. One implant is reachable over the network while the other exploits Bluetooth Low Energy to target the router's Locomotion PC. The supply-chain nature of these implants, present from factory, makes detection difficult and affects all devices shipped with the vulnerable firmware.

Relevance score: 80.0/100

# More from August 29