Affected Systems

ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020. CVE-2026-74232 (SPEAKINGSTONE) affects 15+ models including L3_V2_8, WE826-T2, ZBT-7628, and MoreQuick MQAC/MQAP series. Devices sold under multiple brand names with MAC prefixes 78:A3:51 and F8:5E:3C. At least 203 DARKLANTERN and 392 SPEAKINGSTONE instances detected globally.

Exploitation Status

Active exploitation confirmed. SPEAKINGSTONE beaconed to VulnCheck-controlled backup C2 from 392 unique devices (390 in China, primarily China Mobile network). 203 internet-facing DARKLANTERN instances identified across 22 countries. VulnCheck flags CVE-2026-74233 as exploited in the wild in their KEV catalog. These are factory-installed implants, not post-compromise backdoors.

Business Impact

Unauthenticated remote attackers gain root command execution on affected routers. SPEAKINGSTONE (CVE-2026-74232) beacons outbound to C2 over UDP/10000, bypassing NAT and basic egress filters; supports arbitrary command execution, credential exfiltration (WAN PPPoE passwords), DNS hijacking, and reverse SSH tunnels. DARKLANTERN (CVE-2026-74233) listens on UDP/9992 with ineffective authentication using hardcoded salt and wildcard MAC bypass. CVSS 9.8 (v3.1) / 9.3 (v4.0) for both. No patched firmware available. Devices function as persistent surveillance infrastructure with full root access. Related to ENDLESSDOORS implant (CVE-2026-66747) disclosed August 5 in 20+ Zbtlink models.

Urgency

đź”´ Immediate

Recommended Actions

  • Identify ZBT-manufactured devices by MAC address prefixes 78:A3:51 and F8:5E:3C; cross-reference against affected model list (WE1326, WE826-T2, WE5926, L3_V2_8, ZBT-7628, MoreQuick MQAC/MQAP series, etc.) regardless of brand label
  • Block outbound UDP traffic to port 10000 and domains www.ac-link[.]com, www.findmyipaddr[.]com, and IP 47.107.224[.]89 at perimeter firewalls to prevent SPEAKINGSTONE C2 communication
  • Block inbound connections to UDP port 9992 and outbound on UDP port 8897 to mitigate DARKLANTERN command injection; monitor for processes yunmgrd and infosrvd
  • Search filesystem for IoCs: /etc/exec/cmd, /tmp/info.txt, /tmp/yunclient.conf, and SHA-256 hashes b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818 (yunmgrd) and 7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245 (infosrvd)
  • Replace affected ZBT routers with devices from alternate vendors; no patched firmware is available and implants are factory-installed in supply chain

---

# Geopolitical Context

Geopolitical Context

VulnCheck disclosed two factory-embedded implants (SPEAKINGSTONE and DARKLANTERN) in routers manufactured by Shenzhen Zhibotong Electronics that provide unauthenticated remote root access. SPEAKINGSTONE beacons to a hardcoded command-and-control server, with 392 devices—390 in China—connecting to an unregistered backup domain, predominantly on China Mobile's network. DARKLANTERN listens on an internet-exposed port with ineffective authentication. The implants' capabilities—command execution, credential exfiltration, DNS hijacking, and reverse SSH tunnels—are consistent with surveillance infrastructure. The discovery follows VulnCheck's August disclosure of ENDLESSDOORS, another implant in Zbtlink routers, suggesting a pattern of supply chain compromise in low-cost networking equipment from Chinese manufacturers. The devices are white-labeled and sold globally under multiple brands, complicating vendor accountability and remediation.

State Actor Alignment

No formal attribution to state actors has been published. The implants' design—persistent C2 infrastructure, outbound beaconing to evade NAT, and surveillance-oriented capabilities—is consistent with state-sponsored supply chain operations. The concentration of SPEAKINGSTONE beacons within China (390 of 392 devices) and on China Mobile's network (83 percent) may indicate domestic monitoring infrastructure, though the implants' presence in export models sold to U.S. and international markets raises questions about intent and scope. The hardcoded C2 domain (www.ac-link[.]com) resolving to Alibaba Cloud infrastructure in Shenzhen suggests operational ties to Chinese hosting providers. No sanctions or policy responses have been announced as of late August 2026.

Business Impacty pro region

The global distribution of affected devices—203 DARKLANTERN instances across 22 countries and white-labeled sales through U.S. suppliers—exposes critical infrastructure and enterprise networks to potential compromise. European and North American operators using low-cost Chinese networking equipment face elevated risk, particularly where devices are deployed in SOHO, industrial, or remote-access scenarios. The implants' ability to function behind NAT and standard firewalls complicates detection. The absence of published firmware fixes leaves operators without clear remediation paths. This incident reinforces concerns about supply chain integrity in telecommunications equipment from Chinese manufacturers, echoing broader Western policy debates over Huawei and ZTE. Regulatory bodies may face pressure to expand procurement restrictions or mandate supply chain audits for networking hardware.

Forecast

If additional ZBT or Zbtlink models are found to contain similar implants, expect heightened scrutiny of Chinese-manufactured networking equipment in Western markets and potential expansion of entity lists or import restrictions. If exploitation in the wild is confirmed beyond proof-of-concept, CISA and European cybersecurity agencies may issue emergency directives mandating device replacement in critical sectors. If the C2 infrastructure remains active and additional beaconing devices are identified outside China, attribution efforts may intensify, potentially triggering diplomatic responses or coordinated advisories from Five Eyes partners. Absent firmware patches, affected devices are likely to remain exploitable indefinitely, creating persistent risk in networks where replacement is cost-prohibitive.