Skip to content
See the World Through Science

Security Researchers Find Two More Backdoors in Rebranded Budget Routers

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The bare green circuit board of a consumer wireless router, lifted out of its case, showing two large chips, memory, rows of capacitors and a metal four-port Ethernet block.
The mainboard of a consumer wireless router, carrying the processor and the flash memory that holds its firmware. Illustrative image of router hardware; this is not one of the ZBT-built models VulnCheck examined."Thomson Speedtouche 580i WiFi Modem Router" by Remko van Dokkum, via flickr, CC-BY-2.0 · CC-BY-2.0

The security firm VulnCheck said on Aug. 27 that it had found two more implants built into the shipped firmware of routers made by Shenzhen Zhibotong Electronics, or ZBT, and that its own internet scan counted 203 exposed devices running one of them.

The two are the second and third such components the firm has documented in ZBT firmware. It described the first, ENDLESSDOORS, earlier in August. Both new implants came off a single ZBT-WE826-T2, sold under another company's brand, that VulnCheck said it bought from a U.S. supplier for $88.

DARKLANTERN accepts commands sent to it from the internet and runs them with full control of the device and no password required, VulnCheck said. SPEAKINGSTONE works the other way around, calling out to a server on ZBT's own cloud infrastructure and waiting for instructions. The firm said those instructions can change the router's DNS settings, which steer a network's traffic; copy the credentials the router uses to reach its internet provider; and open a remote login tunnel.

Between Aug. 18 and Aug. 21, VulnCheck's own internet scanner identified 203 internet-facing DARKLANTERN instances across 22 countries, the report said, and the devices that answered reported 16 different models. VulnCheck also registered an unclaimed backup domain that SPEAKINGSTONE falls back on and logged what connected: 392 devices as of Aug. 21, 390 of them in China.

VulnCheck assigned the two identifiers itself, as a CVE Numbering Authority: CVE-2026-74232 for SPEAKINGSTONE and CVE-2026-74233 for DARKLANTERN, both published Aug. 27 and both scored 9.3 out of 10 on the firm's own severity rating. The DARKLANTERN record lists 16 affected models; the SPEAKINGSTONE record lists 15. Neither names a fixed firmware version.

ZBT hardware is resold under other companies' names in the United States, Canada, Australia, Germany, the Philippines and Russia, VulnCheck said, citing FCC filings and trademark records. In response to the earlier ENDLESSDOORS report, VulnCheck said, ZBT described that component as an "after-sales technical support tool" and said it "has never been used for unauthorized access."

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Security Researchers Find Two More Backdoors in Rebranded Budget Routers

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.