Recent research by VulnCheck has uncovered two previously undocumented factory implants in the firmware of routers produced by Shenzhen Zhibotong Electronics (ZBT). These implants, identified as SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to execute commands with root privileges on affected devices.
Details of the Vulnerabilities
The vulnerabilities are tracked as CVE-2026-74232 for SPEAKINGSTONE and CVE-2026-74233 for DARKLANTERN. Both vulnerabilities have received a high severity rating of 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1. They require no user interaction or privileges to exploit, making them particularly concerning.
Functionality of the Implants
SPEAKINGSTONE operates as the service yunmgrd and communicates with a hardcoded command-and-control (C2) server over UDP port 10000. This implant can execute arbitrary commands, exfiltrate sensitive information such as WAN PPPoE credentials, and establish a reverse SSH tunnel. VulnCheck has characterized it as a surveillance implant with comprehensive access to the devices it infects.
DARKLANTERN, functioning as the service infosrvd on UDP port 9992, is particularly vulnerable due to its ineffective authentication mechanism, which relies on a hardcoded salt and a wildcard MAC address. This allows any internet address to connect to it, significantly increasing the risk of exploitation.
Scope of the Issue
VulnCheck identified 203 instances of DARKLANTERN across 22 countries, with a significant number of devices reporting from China. The implants were found on a specific model, the ZBT-WE826-T2, purchased from a U.S. supplier, indicating that the issue may affect multiple models and firmware versions. The advisory lists several affected models and firmware builds for both vulnerabilities, but no fixed firmware release has been announced.
Current Status and Recommendations
As of now, ZBT has not publicly addressed the presence of these implants in their firmware. VulnCheck has recommended blocking inbound traffic to UDP port 9992 to mitigate the risk associated with DARKLANTERN. Additionally, they have published indicators of compromise (IoCs) to assist in identifying affected devices and monitoring network traffic.
The situation remains fluid, and further updates from ZBT or VulnCheck may provide additional clarity on the extent of the vulnerabilities and any potential patches.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








