← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

Security Researchers Discover Three Backdoor Implants in ZBT Routers Sold Globally

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Three implants (ENDLESSDOORS, DARKLANTERN, SPEAKINGSTONE) found in ZBT router firmware.
  • ENDLESSDOORS allows arbitrary command execution as root and phones home to a C2 server.
  • DARKLANTERN exposes device information via an unauthenticated WAN port.
  • ZBT routers are sold globally under various OEM/ODM brands.

Discovery of ENDLESSDOORS Implant

Security researchers at VulnCheck uncovered a backdoor-like implant, dubbed ENDLESSDOORS, in the firmware of Zbtlink AX3000 routers and 20 other ZBT models. This implant operates as a remote-control system, disguising itself as a Linux kernel process, and automatically connects to a command-and-control server. It can execute arbitrary commands as root and establish an interactive root shell without meaningful authentication or encryption.

Demonstrated Vulnerability and CVE Assignment

VulnCheck demonstrated the implant's vulnerability by impersonating the command server and taking control of a test router, confirming that an attacker could gain complete control if they hijacked the connection. The issue, affecting models like the Z8102AX and WG3526, was assigned CVE-2026-66747 with a CVSS score of 9.3.

Additional Implants: DARKLANTERN and SPEAKINGSTONE

Further investigation of a white-labeled ZBT-WE826-T2 router, sold as a Deep Orange cellular router, revealed two more implants: DARKLANTERN and SPEAKINGSTONE. DARKLANTERN, operating as the infosrvd service, opens a listener on WAN via UDP port 9992. It accepts commands directly from the internet without authentication, allowing an attacker to send a 19-byte probe to force the router to reveal identifying information such as its model, firmware version, MAC address, and uptime.

Widespread Impact Due to OEM/ODM Sales

The widespread nature of this vulnerability stems from ZBT's business model, where it manufactures routers for various OEM and ODM customers. This means that many devices sold under different brand names globally may contain these implants, making it difficult for users to identify if they are using an affected ZBT-manufactured router.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Aug 28

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security firm VulnCheck identified three distinct backdoor-like implants, named ENDLESSDOORS, DARKLANTERN, and SPEAKINGSTONE, embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT), which are sold worldwide under various brands. These implants allow for remote command execution and information disclosure, posing significant security risks to users of affected devices. The discovery highlights a widespread supply chain vulnerability in networking hardware.