Security researchers at VulnCheck have disclosed two previously undocumented firmware implants embedded directly into routers manufactured by Shenzhen Zhibotong Electronics (ZBT). The backdoors, tracked as CVE-2026-74232 and CVE-2026-74233, grant unauthenticated remote attackers full root-level control over affected devices. Unlike conventional vulnerabilities that require post-deployment exploitation, these implants are compiled into the firmware during the manufacturing process, delivering pre-compromised devices directly from the factory.

Designated SPEAKINGSTONE and DARKLANTERN, the implants bypass traditional attack chains entirely. Compromised devices arrive on-premises with remote command execution capabilities already enabled, requiring no credential theft, user interaction, or prior network foothold to trigger. The risk is compounded by ZBT’s role as an original design manufacturer (ODM). Identical compromised firmware is routinely rebranded and distributed across multiple global product lines, silently multiplying the attack surface and complicating asset inventory for downstream vendors and enterprise buyers.

Immediate Containment Guidance Organizations deploying ZBT-manufactured gateways or rebranded variants should immediately isolate affected devices from critical network segments and disable all remote management interfaces. Security teams are advised to deploy VulnCheck’s published indicators of compromise (IOCs) to monitor for anomalous outbound traffic patterns associated with the implants. Due to their firmware-level persistence and lack of standard configuration footprints, conventional vulnerability scanners and routine configuration audits will likely fail to detect the backdoors.

Procurement and Compliance Shift The disclosure underscores a critical baseline shift in infrastructure security: firmware provenance can no longer be treated as optional. Procurement and compliance policies must transition to zero-trust models that mandate cryptographic signature verification, baseline checksum validation, and independent binary auditing prior to deployment. Long-term resilience will depend on industry-wide adoption of reproducible build pipelines and hardware attestation frameworks, ensuring deployed firmware cryptographically matches auditable source code.

Unresolved Gaps Several operational hurdles remain. A comprehensive public inventory detailing affected ZBT hardware models and firmware revisions has not been published, hindering accurate network discovery and risk scoping. Neither ZBT nor downstream OEMs have released official patches, firmware updates, or a formal remediation timeline. Furthermore, independent binary auditing remains resource-intensive, leaving organizations without scalable, low-barrier methods to verify firmware integrity without specialized tooling or vendor cooperation.

While the vulnerability originates from a single upstream manufacturer, the implications extend across global IT operations. Network administrators and compliance teams should treat supply-chain verification as a foundational security control. As embedded infrastructure faces increasingly sophisticated targeting, the industry must transition from reactive patching to verifiable, transparent build processes.


VulnCheck的安全研究人員披露,由深圳市智博通電子(ZBT)製造的路由器韌體中,內置了兩款此前未公開的firmware implants。這兩款後門(編號CVE-2026-74232及CVE-2026-74233)容許未經認證的遠端攻擊者完全取得受影響裝置的root權限。與一般需於部署後才被利用的漏洞不同,這些植入程式是在製造過程中直接編譯至韌體內,直接由工廠交付已預先遭入侵的裝置。

代號SPEAKINGSTONE及DARKLANTERN的植入程式完全繞過傳統攻擊鏈。受影響裝置送抵客戶端時,遠端指令執行功能已預設開啟,無需竊取憑證、用戶互動或事先取得網絡立足點即可觸發。ZBT作為原始設計製造商(ODM)的身份進一步加劇了相關風險。相同的遭篡改韌體會慣常以貼牌形式分銷至全球多條產品線,無形中擴大攻擊面,並為下游供應商及企業買家的資產清查帶來困難。

即時遏制指引 部署ZBT製造的閘道器或貼牌型號的機構,應立即將受影響裝置與關鍵網絡區段隔離,並停用所有遠端管理介面。建議保安團隊部署VulnCheck公佈的IOCs,以監察與該植入程式相關的異常外發流量模式。鑑於該後門具備韌體層級的持久性,且缺乏標準配置指紋,傳統漏洞掃描工具及常規配置審計很可能無法偵測到這些後門。

採購與合規方針轉型 是次披露凸顯基礎設施保安的關鍵基準轉變:韌體來源現不能再被視為可選項目。採購及合規政策必須轉向零信任模式,於部署前強制執行數碼簽章驗證、baseline checksum validation,以及獨立binary auditing。長遠而言,業界能否建立韌性,將取決於能否廣泛採用reproducible build pipelines及hardware attestation frameworks,以確保已部署的韌體在密碼學層面與可審計的原始碼完全一致。

現存未解難題 目前仍有數項營運障礙尚未解決。官方尚未公佈詳列受影響ZBT硬件型號及韌體版本的完整清單,阻礙準確的網絡資產偵測與風險界定。ZBT及下游OEM均未發佈官方修補程式、韌體更新或正式的修復時間表。此外,獨立binary auditing依然耗費大量資源,令機構在缺乏專用工具或供應商配合的情況下,難以採用具擴展性且門檻較低的方法來驗證韌體完整性。

儘管該漏洞源於單一上游製造商,其影響卻遍及全球IT營運。網絡管理員及合規團隊應將供應鏈驗證視為基礎保安控制措施。隨著嵌入式基礎設施面臨日益複雜的針對性攻擊,業界必須由被動修補,轉向可驗證且透明的build process。

新聞來源 / Original News Source