중국 ZBT 라우터에 인증 없이 루트 접근을 허용하는 두 개의 임플란트가 발견됐다.
VulnCheck에 의해 중국의 ZBT 라우터 펌웨어에 두 개의 문서화되지 않은 공장 임플란트가 발견되었다. 이 임플란트는 각각 인증 없는 원격 공격자가 영향을 받은 장치에서 루트 권한으로 명령을 실행할 수 있게 해준다. 해당 임플란트는 SPEAKINGSTONE 및 DARKLANTERN으로 이름 붙여졌으며, CVE-2026-74232와 CVE-2026-74233으로 추적된다.
Two implants found in China-made ZBT routers allow unauthenticated root access.
VulnCheck has disclosed two undocumented factory implants in the firmware of routers made by Shenzhen Zhibotong Electronics (ZBT). These implants allow unauthenticated remote attackers to execute commands as root on the affected devices. Named SPEAKINGSTONE and DARKLANTERN, they are tracked as CVE-2026-74232 and CVE-2026-74233.