
ACCORDING to a report by securityonline.info, researchers have uncovered two critical backdoors in ZBT routers that grant unauthenticated root access from the internet. The exposure puts devices in over twenty countries at risk of full compromise.
The flaws are tracked as CVE-2026-74232 and CVE-2026-74233, each rated CVSS 9.8, and correspond to the backdoors named DarkLantern and SpeakingStone (VulnCheck) that abuse open UDP ports to execute privileged commands on the affected firmware. Successful exploitation gives an attacker complete control over the device, allowing them to alter configuration, intercept traffic, and use the router as a pivot into internal networks.
Once exploited, the backdoors give attackers a root shell and enable the router to initiate outbound connections to attacker‑controlled domains, facilitating surveillance and data theft as outlined in a separate analysis by darkreading.com. The ability to reach external command and control servers means that compromised routers can be used for data exfiltration or to launch further attacks downstream.
Although no specific threat actor has been linked to the vulnerabilities, researchers confirm that the affected models are already in live deployments across more than twenty nations, creating a serious supply chain concern for organisations that rely on low‑cost networking gear. The presence of these backdoors in widely distributed hardware highlights the risk of trusting firmware from opaque sources without independent verification.
Defenders should immediately remove any identified ZBT routers from sensitive networks, block inbound traffic on the abnormal UDP ports observed in the exploit, and monitor logs for unexpected outbound connections to unknown domains. Where removal is not feasible, administrators are advised to segment the devices behind strict firewalls and disable any unnecessary services. Planning for replacement with hardware from vendors that provide timely security updates is the safest long‑term mitigation.
Network defenders should also consider implementing egress filtering to prevent compromised routers from reaching malicious domains. Staying vigilant for anomalous traffic patterns and regularly auditing inventory will help detect similar supply chain issues in the future.