mimile
Back to feed

China-Made ZBT Routers Ship With Two Implants Giving Attackers Root Access

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

China-Made ZBT Routers Ship With Two Implants Giving Attackers Root Access

VulnCheck disclosed two undocumented factory implants in ZBT routers that let unauthenticated remote attackers run commands as root. The implants, SPEAKINGSTONE and DARKLANTERN, are rated 9.3 on CVSS 4.0 and affect at least 16 models. VulnCheck found 203 internet-facing DARKLANTERN instances across 22 countries between August 18 and 21.

Key Facts

  • SPEAKINGSTONE runs as service yunmgrd and sends beacons over UDP port 10000 to a hardcoded command-and-control server.
  • DARKLANTERN operates as service infosrvd on UDP port 9992, which the stock firewall opens to inbound connections from any internet address.
  • VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries between August 18 and August 21.
  • Both implants were found on an $88 Deep Orange 3G/4G/LTE Router, a white-labeled ZBT-WE826-T2 with firmware built in 2019.
  • The affected models include Zbtlink WE826-T2, WE1326, WE357, WE5926, and WG3526, among others.

SPEAKINGSTONE Implant

SPEAKINGSTONE runs as the service yunmgrd and sends beacons over UDP port 10000 to a hardcoded command-and-control server. Because the implant dials outward, it functions from behind NAT and ordinary egress filtering. Its protocol supports message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, write and read a DNS hijack list, and open a reverse SSH tunnel. VulnCheck described it as a surveillance implant with root access to every device it runs on.

DARKLANTERN Implant

DARKLANTERN operates as the service infosrvd on UDP port 9992, which the router's stock firewall opens to inbound connections from any internet address. VulnCheck's advisory describes the service's authentication as ineffective, resting on a hardcoded salt and an all-zero wildcard MAC value that bypasses its own address check. Between August 18 and August 21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries, self-reporting 16 distinct models. The figure counts hosts that answered a probe rather than devices found compromised.

Affected Models and Discovery

Both implants were found on an $88 Deep Orange 3G/4G/LTE Router bought from a U.S. supplier, a white-labeled ZBT-WE826-T2 whose firmware was built in 2019. That unit predates ENDLESSDOORS (CVE-2026-66747), the phone-home implant VulnCheck disclosed on August 5 and found in at least 20 Zbtlink router models. VulnCheck's advisory for the DARKLANTERN command injection names models including Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108 and WG3526 on firmware 19.1101. The SPEAKINGSTONE advisory lists Zbtlink L3_V2_8 on 3.0.0.4.528, WE826-T2 on 19.1101, ZBT-7628 on 1.0.0.2.007 and ZBT-ZBT7621 on 1.0.0.3.001, among others.

2 sources

China-Made ZBT Routers Ship With Two Implants Giving Attackers Root Access