CVE Tools
Back to feed
PoC public ZBT WE826-T2 supply-chain Deep Orange 3G/4G/LTE Router Shenzhen Zhibotong Electronics ics-ot-iot

В роутерах ZBT обнаружили еще два бэкдора

Хакер (xakep.ru)·By Мария Нефёдова··3 min read
CVE Tools coverage

Security firm VulnCheck has identified two previously unknown root-level implants, dubbed SPEAKINGSTONE and DARKLANTERN, within the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These vulnerabilities, assigned CVE-2026-74232 and CVE-2026-74233, allow remote attackers to execute arbitrary commands without authentication, earning them high severity scores of 9.8 on CVSS 3.1.

SPEAKINGSTONE operates as a persistent service that exfiltrates data over UDP port 10000, enabling actions such as PPPoE credential theft and reverse SSH tunneling, while DARKLANTERN exposes a vulnerable command interface on UDP port 9992 where security checks can be easily bypassed. The discovery follows a similar finding in July regarding the ENDLESSDOORS implant, reinforcing concerns about the inherent risks in ZBT's OEM business model where identical hardware is sold under multiple brands.