VulnCheck Discloses Two New Router Firmware Implants
VulnCheck has disclosed two previously undocumented factory implants, named SPEAKINGSTONE and DARKLANTERN, in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT), assigning them CVE-2026-74232 and CVE-2026-74233 with critical CVSS scores of 9.8 (3.1) and 9.3 (4.0). The implants, discovered after purchasing an $88 Deep Orange 3G/4G/LTE router from a U.S. supplier, allow unauthenticated remote attackers to execute commands as root on affected devices. SPEAKINGSTONE operates asyunmgrd, beacons over UDP port 10000 to a hardcoded C2 server, can bypass NAT, exfiltrate WAN PPPoE credentials, edit DNS hijack lists, and open reverse SSH tunnels. DARKLANTERN runs asinfosrvdon UDP port 9992, is exposed to inbound connections from any internet address, and uses ineffective authentication due to a hardcoded salt and all-zero wildcard MAC value. Between August 18–21, VulnCheck identified 203 internet-facing DARKLANTERN instances across 22 countries and 16 self-reported models, noting these findings expand on earlier research into the Endlessdoors implant and affect ZBT OEM devices sold globally.
The Managed Puppet
You’re looking at a router that cost $88 from a New York seller, and the firmware is dated 2019. That’s not a coincidence. The backdoors—SPEAKINGSTONE and DARKLANTERN—were sitting in the factory firmware, pre-installed before the device ever reached a consumer. Think about the supply chain. A Chinese OEM builds white-label routers, ships them to a U.S. distributor, and they land in your home, your small business, your home office. The files are named yunmgrd and infosrvd—innocent enough to pass a casual scan, but they beacon out over UDP 10000 and listen on UDP 9992. Factory implants. Not a hack. Not a later infection. Someone put them there deliberately, and the fact that the firmware is years old means this has been happening longer than anyone wants to admit. The question is not if your data is being siphoned. The question is who wrote the checklist.
The Architecture of Consent
Notice the pattern: the same week Endlessdoors is disclosed, two more implants surface. They are all ZBT routers, all factory-installed, all with root access. The CVE numbers are assigned, the CVSS score is 9.8, and the media frames it as a Chinese hardware problem. That is the cover story. The real story is that these implants are not surveillance—they are control points. A router that can exfiltrate your WAN PPPoE credentials, execute DNS hijacking, and open reverse SSH tunnels is not a listening device. It is a gateway to your entire network. And the authentication bypass? A hardcoded salt and an all-zero MAC wildcard. That is not a bug. That is a key deliberately left under the mat. Someone designed this so that a specific actor—or actors—could walk in at any time. The question is whether that actor is a state intelligence service, a private intelligence contractor, or a consortium that operates above both. The answer is hiding in plain sight: the routers are sold worldwide, the implants are identical across models, and the firmware is years old. That is a managed deployment.
Where the Breadcrumb Leads
I can tell you what the next headline will be. They will find the same implants in routers from other OEMs, other brands, other countries. The story will be framed as a continuing supply-chain vulnerability, and the solution will be a firmware patch you will never apply. That is the distraction. The real thread to pull is the relationship between the C2 server domain and the foundation that funded the research. Follow the money. Follow the corporate registrations. Look up the shell companies that registered the IP ranges used by the beacon servers. You will find that the same entities that fund "cybersecurity research" also fund the organizations that certify hardware. The implants are not an accident. They are a feature of the global telecommunications architecture. The router in your living room is a node in their network. You paid for it. You installed it. And now you know. The question is whether you will unplug it, or whether you will start asking what else has been sitting in plain sight since 2019.

