Security Researchers Find Two More Backdoors in Rebranded Budget Routers

The security firm VulnCheck said on Aug. 27 that it had found two more implants built into the shipped firmware of routers made by Shenzhen Zhibotong Electronics, or ZBT, and that its own internet scan counted 203 exposed devices running one of them.
The two are the second and third such components the firm has documented in ZBT firmware. It described the first, ENDLESSDOORS, earlier in August. Both new implants came off a single ZBT-WE826-T2, sold under another company's brand, that VulnCheck said it bought from a U.S. supplier for $88.
DARKLANTERN accepts commands sent to it from the internet and runs them with full control of the device and no password required, VulnCheck said. SPEAKINGSTONE works the other way around, calling out to a server on ZBT's own cloud infrastructure and waiting for instructions. The firm said those instructions can change the router's DNS settings, which steer a network's traffic; copy the credentials the router uses to reach its internet provider; and open a remote login tunnel.
Between Aug. 18 and Aug. 21, VulnCheck's own internet scanner identified 203 internet-facing DARKLANTERN instances across 22 countries, the report said, and the devices that answered reported 16 different models. VulnCheck also registered an unclaimed backup domain that SPEAKINGSTONE falls back on and logged what connected: 392 devices as of Aug. 21, 390 of them in China.
VulnCheck assigned the two identifiers itself, as a CVE Numbering Authority: CVE-2026-74232 for SPEAKINGSTONE and CVE-2026-74233 for DARKLANTERN, both published Aug. 27 and both scored 9.3 out of 10 on the firm's own severity rating. The DARKLANTERN record lists 16 affected models; the SPEAKINGSTONE record lists 15. Neither names a fixed firmware version.
ZBT hardware is resold under other companies' names in the United States, Canada, Australia, Germany, the Philippines and Russia, VulnCheck said, citing FCC filings and trademark records. In response to the earlier ENDLESSDOORS report, VulnCheck said, ZBT described that component as an "after-sales technical support tool" and said it "has never been used for unauthorized access."
