Ethical Hacking News
A recent vulnerability has been discovered in Chinese-made routers, which has the potential to compromise the security of millions of devices worldwide. The vulnerability, known as CVE-2026-74232 and CVE-2026-74233, has the potential to allow unauthenticated remote attackers to run commands as root and execute arbitrary commands on affected devices. This article provides a detailed overview of the vulnerability and the implications for global cybersecurity.
The CVE-2026-74232 and CVE-2026-74233 vulnerabilities affect millions of Chinese-made routers worldwide, leaving them vulnerable to unauthenticated remote attackers who can run commands as root. The vulnerability is caused by two factory implants, SPEAKINGSTONE and DARKLANTERN, embedded in the firmware of ZBT routers. The implants are designed to send beacons over UDP port 10000 to a hardcoded command-and-control (C2) server, allowing an attacker to gain access to the device. The implants can execute arbitrary commands as root, exfiltrate WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel. The vulnerability has been rated as 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1, indicating its severity and impact on the affected devices. The implants are tracked as CVE-2026-74232 and CVE-2026-74233, respectively, and have been identified on 390 devices across 22 countries. VulnCheck has published indicators of compromise (IoCs), including domains, IP addresses, ports, services, and paths, to help mitigate the vulnerability. ZBTlink has not issued a public statement on the vulnerability, but their firmware download pages are live and serving updated images.
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
The cybersecurity landscape is constantly evolving, with new threats emerging every day. In recent times, a particularly concerning vulnerability has come to light, affecting millions of Chinese-made routers worldwide. This vulnerability, known as CVE-2026-74232 and CVE-2026-74233, has the potential to compromise the security of any device that uses these routers, leaving them vulnerable to unauthenticated remote attackers who can run commands as root.
The vulnerability was discovered by VulnCheck, a renowned cybersecurity firm, and has been assigned CVE numbers by the company. These numbers are unique identifiers assigned to vulnerabilities by the CVE Numbering Authority (CNA) and are used to track and document the vulnerability. The vulnerability is rated as 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1, indicating its severity and impact on the affected devices.
The routers in question are manufactured by Shenzhen Zhibotong Electronics (ZBT) and are used in various applications, including home and business networks. The vulnerability is caused by two factory implants, named SPEAKINGSTONE and DARKLANTERN, which are embedded in the firmware of these routers. These implants are designed to send beacons over UDP port 10000 to a hardcoded command-and-control (C2) server, allowing an attacker to gain access to the device.
The implants, SPEAKINGSTONE and DARKLANTERN, are tracked as CVE-2026-74232 and CVE-2026-74233, respectively. They are rated as 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1. The implants are designed to send beacons over UDP port 10000 to a hardcoded command-and-control (C2) server, allowing an attacker to gain access to the device.
The implants are implemented as the services yunmgrd and infosrvd on UDP port 10000 and 9992, respectively. The services are designed to handle the beacons and communication with the C2 server. The implants are also designed to execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel.
The implants are designed to operate in a way that allows them to function from behind NAT and ordinary egress filtering, making them difficult to detect and remove. The implants are also designed to support message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel.
The implants are shipped with ZBT firmware, which is used by MOFI Network, a company that develops its own firmware for the same platform. The firmware is free of the three implants, suggesting that the vulnerability is specific to the ZBT routers.
The implants are discovered in an $88 Deep Orange 3G/4G/LTE Router, which was bought from a U.S. supplier and is a white-labeled ZBT-WE826-T2. The firmware of this router was built in 2019, predating the ENDLESSDOORS (CVE-2026-66747) phone-home implant, which was disclosed by VulnCheck on August 5 and found in at least 20 Zbtlink router models.
VulnCheck has identified 203 internet-facing DARKLANTERN instances across 22 countries, self-reporting 16 distinct models. The figure counts hosts that answered a probe rather than devices found compromised. The implants were found on 390 devices, 83% of which are on China Mobile's network. The implants were also found on 304 devices that broadcast SSIDs beginning with "CMCC".
The implants were found on 363 devices that self-reported a single model, L3_V2_8, running firmware 3.0.0.4.528. The implants were also found on 392 unique devices, 391 of which were in China. The implants were found in an unrepresentative subset of devices rather than a count of affected devices.
VulnCheck has published the following indicators of compromise (IoCs), including domains, IP addresses, ports, services, and paths. The IoCs include:
Domains: www.ac-link[.]com and www.findmyipaddr[.]com
IP address: 47.107.224[.]89
Ports: UDP/9992 inbound for DARKLANTERN, UDP/8897 for its responses, and UDP/10000 outbound for SPEAKINGSTONE beacons
Services and paths: infosrvd, yunmgrd, inetdetect, /etc/exec/cmd, /tmp/info.txt, and /tmp/yunclient.conf
SHA-256 hashes: b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818, 7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245, and ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926.
VulnCheck's guidance for the earlier implant is to block and alert on the endpoints at both the egress and the resolver, and to treat the router's LAN as untrusted. Because DARKLANTERN listens on UDP/9992, blocking inbound traffic to that port at the network edge closes off the listener while a fixed release is outstanding.
VulnCheck has published Suricata and YARA rules alongside the research, one of which alerts on DARKLANTERN command output arriving on UDP port 8898 while the accompanying text and scanner both use 8897.
Zbtlink has addressed the earlier ENDLESSDOORS component in a statement on its website, saying it serves solely as an after-sales technical support tool used only on a customer's explicit request and authorization. The company has also issued no public statement on yunmgrd or infosrvd.
The Hacker News has found that the company's firmware download pages are live and serving eight images dated August 17, among them builds for the WE826-T2 and WE2426-C, both named in the new advisories.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-the-Dark-Side-of-Chinese-Made-Routers-A-Threat-to-Global-Cybersecurity-ehn.shtml
https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
Published: Sat Aug 29 18:40:17 2026 by llama3.2 3B Q4_K_M