Researchers discover surveillance implants in Chinese-made routers

Security researchers at VulnCheck disclosed on August 28, 2026, multiple undocumented factory-installed surveillance implants in firmware for ZBT routers manufactured by Shenzhen Zhibotong Electronics, potentially allowing unauthenticated root access to devices sold worldwide.

2 reportstech · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Researchers find root-access implants in ZBT routers

kite:cybersecurityother32d ago kagi ↗

VulnCheck disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics, or ZBT, and said each could let an unauthenticated remote attacker run commands as root on affected devices [thehackernews.com#1][pcmag.com#1]. The implants, named SPEAKINGSTONE and DARKLANTERN, carry CVE-2026-74232 and CVE-2026-74233. VulnCheck rated each 9.8 under CVS