Security researchers at VulnCheck uncovered a backdoor-like implant, dubbed ENDLESSDOORS, in the firmware of Zbtlink AX3000 routers and 20 other ZBT models. This implant operates as a remote-control system, disguising itself as a Linux kernel process, and automatically connects to a command-and-control server. It can execute arbitrary commands as root and establish an interactive root shell without meaningful authentication or encryption.
VulnCheck demonstrated the implant's vulnerability by impersonating the command server and taking control of a test router, confirming that an attacker could gain complete control if they hijacked the connection. The issue, affecting models like the Z8102AX and WG3526, was assigned CVE-2026-66747 with a CVSS score of 9.3.
Further investigation of a white-labeled ZBT-WE826-T2 router, sold as a Deep Orange cellular router, revealed two more implants: DARKLANTERN and SPEAKINGSTONE. DARKLANTERN, operating as the infosrvd service, opens a listener on WAN via UDP port 9992. It accepts commands directly from the internet without authentication, allowing an attacker to send a 19-byte probe to force the router to reveal identifying information such as its model, firmware version, MAC address, and uptime.
The widespread nature of this vulnerability stems from ZBT's business model, where it manufactures routers for various OEM and ODM customers. This means that many devices sold under different brand names globally may contain these implants, making it difficult for users to identify if they are using an affected ZBT-manufactured router.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security firm VulnCheck identified three distinct backdoor-like implants, named ENDLESSDOORS, DARKLANTERN, and SPEAKINGSTONE, embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT), which are sold worldwide under various brands. These implants allow for remote command execution and information disclosure, posing significant security risks to users of affected devices. The discovery highlights a widespread supply chain vulnerability in networking hardware.