ZBT Router Firmware Implants Expose Root-Level Control Risk
VulnCheck found three backdoor-like implants in ZBT-made or white-label routers, including 203 exposed DARKLANTERN instances across 22 countries and sinkhole traffic from 392 devices.

Security researchers found firmware implants that can give remote operators root-level control of ZBT-made routers, Tom's Hardware reported, after VulnCheck traced three separate control mechanisms across globally sold hardware and white-label models.
The research began with a Zbtlink AX3000 router from Shenzhen Zhibotong Electronics, better known as ZBT.
Its firmware contained ENDLESSDOORS, an implant that starts at boot, uses the ordinary Linux process name kworker and contacts a hard-coded command-and-control server.
ENDLESSDOORS leaves the router exposed beyond an ordinary software flaw.
Server commands pass into a root shell, and VulnCheck demonstrated control by posing as the command server on its own test device.
The implant appeared across 20 ZBT router models; Z8102AX, WG3526 and WE826-T3-DSIM were among the named examples, and the issue is tracked as CVE-2026-66747.
A second test widened the issue from one router line to white-label hardware.
An $88 Deep Orange cellular router bought from a US Amazon seller turned out to be a ZBT-WE826-T2 sold under another brand.
Its older 2019 firmware did not include ENDLESSDOORS but carried two other implants, DARKLANTERN and SPEAKINGSTONE.
DARKLANTERN runs as the infosrvd service and opens UDP port 9992 on the WAN side without authentication.
A fixed 19-byte probe can make the router reveal its model, firmware version, MAC address and uptime, while a static checksum salt and a bypassable MAC filter allow forged packets to run root-level commands.
VulnCheck found 203 exposed DARKLANTERN instances in 22 countries across 16 router models.
SPEAKINGSTONE uses a different control path.
The yunmgrd service beacons out over UDP port 10000 to ZBT command infrastructure, sends device fingerprints through a custom zbtProtocol format and can run commands, steal WAN PPPoE credentials, rewrite a DNS hijack list or establish a reverse SSH tunnel.
The sinkhole evidence pointed mainly to China rather than a broad consumer botnet.
After VulnCheck registered an unclaimed backup command domain embedded in SPEAKINGSTONE, 392 unique devices connected by Aug. 21; 390 were in China, mostly on China Mobile's network, and most appeared to share the same router model and firmware.
ZBT's OEM and ODM business leaves buyers with a supply-chain identification problem.
Affected or related hardware has appeared under brands including Deep Orange, WiFlyer, Cioswi, CroSkylink, KuWFi, Lippert Components, Wave WiFi, OneX, MoFI Network and Digineo, while VulnCheck also noted that some firmware it examined did not contain the implants.
ZBT described ENDLESSDOORS as an after-sales technical-support mechanism.
The security issue remains the absence of trustworthy authentication around code that can operate with root privileges, especially when the same underlying routers may reach customers under names that do not mention ZBT.




















