VulnCheck researchers have identified two factory-installed backdoors in routers manufactured by Shenzhen Zhibotong Electronics (ZBT), a Chinese networking equipment maker. The implants, designated CVE-2026-74232 and CVE-2026-74233, grant unauthenticated remote attackers root-level command execution on affected devices.

The first backdoor, named SPEAKINGSTONE, and the second, DARKLANTERN, were discovered during firmware analysis of ZBT routers. Both implants bypass authentication mechanisms entirely, meaning attackers need no valid credentials to exploit them. Once accessed, an attacker gains root privileges, the highest level of system access possible. From this vantage point, threat actors can execute arbitrary code, harvest network traffic, modify firmware, exfiltrate data, or use the device as a pivot point into connected networks.

Factory implants differ fundamentally from vulnerabilities discovered post-deployment. Rather than arising from coding errors or design oversights, these backdoors appear intentionally built into the firmware before the routers ship to customers. This supply chain compromise creates persistent threats that standard patching processes may not address if the underlying firmware distribution channels remain compromised.

ZBT routers target small business and enterprise environments in addition to retail markets. The routers handle network traffic, DNS resolution, and device authentication for local networks. Compromise at this layer gives attackers exceptional leverage. They can inspect unencrypted traffic, intercept credentials, perform man-in-the-middle attacks against users on the network, or establish persistent footholds for lateral movement into more sensitive systems.

The implants' technical sophistication suggests state-level involvement or coordinated criminal engineering. VulnCheck's naming convention hints at espionage capabilities rather than opportunistic cybercriminal activity. The deliberate nature of the implants and their placement at the manufacturing stage indicate either direct involvement by the hardware vendor or infiltration of the supply chain before distribution.

ZBT's parent region compounds risk assessments. Equipment manufactured in China by companies with ties to state interests invites scrutiny from Western governments. The United States, European Union, and allied nations have increasingly restricted Chinese networking hardware in critical infrastructure, citing exactly these supply chain risks. These two backdoors validate years of warnings from cybersecurity researchers and policymakers about trustworthiness of imported networking equipment.

Organizations currently running ZBT routers face immediate exposure. Attackers can exploit these implants without triggering intrusion detection systems or leaving obvious traces. The unauthenticated nature means even devices isolated from the internet through firewalls remain at risk if any outbound connection exists. A single compromised router can undermine network segmentation, compromise data at rest and in transit, and provide attackers stable staging ground for further attacks.

Response options are limited. Standard firmware updates may not fully address factory implants if the update process itself relies on compromised infrastructure. Complete hardware replacement represents the most secure remediation. Organizations should audit network access from ZBT devices, monitor for suspicious command execution, and assume any sensitive data traversing these routers during the implant period may have been captured.

VulnCheck's disclosure follows responsible disclosure timelines but raises questions about how many other factory implants remain undiscovered in equipment already deployed globally. The discovery reinforces the principle that security boundaries must extend upstream to manufacturing and supply chain validation, not just endpoint hardening.