Threat Intelligence

Chinese-Made ZBT Routers Found With Hidden Backdoors Allowing Full Remote Takeover

The Hacker News · 28 Aug 2026
Key Takeaway Check whether your business uses ZBT-branded routers, apply any available firmware updates immediately, and consider replacing devices from vendors with a history of undisclosed backdoors.

Cybersecurity firm VulnCheck has uncovered two previously unknown backdoors, or 'implants', hidden inside the firmware of routers made by Shenzhen Zhibotong Electronics (ZBT). Named SPEAKINGSTONE and DARKLANTERN, these implants allow an attacker with no login credentials to remotely run commands with full administrator (root) access on the affected devices.

The two flaws have been officially catalogued as CVE-2026-74232 and CVE-2026-74233. Because the implants appear to be built into the firmware at the factory level, rather than introduced through a later hack, they represent a serious supply chain risk — meaning devices could be vulnerable straight out of the box, before a business even connects them to their network.

Routers are a critical piece of business infrastructure, sitting at the gateway between a company's internal systems and the internet. A backdoor at this level could let attackers intercept traffic, pivot into internal networks, or use the device as a launchpad for further attacks — all without needing to steal a password first.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.