< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

ZBT routers found with firmware implants providing root access

Security researchers at VulnCheck have identified two undocumented factory implants, named SPEAKINGSTONE and DARKLANTERN, embedded in the firmware of routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These implants allow unauthenticated remote attackers to gain root access to affected devices.

DARKLANTERN operates via UDP port 9992 and is accessible from the internet due to ineffective firewall settings and authentication bypasses. It allows attackers to execute arbitrary shell commands as root. SPEAKINGSTONE operates via UDP port 10000, initiating outbound connections to a command-and-control server. This implant enables attackers to exfiltrate WAN PPPoE credentials, perform DNS hijacking, and establish reverse SSH tunnels.

The vulnerabilities affect various white-labeled router brands sold globally. Research identified instances of DARKLANTERN across 22 countries, and sinkholing a backup domain revealed hundreds of devices, primarily located in China.

Entities

Shenzhen Zhibotong Electronics · VulnCheck