ZBT Routers CVE-2026-66747: Three Surveillance Implants Found in Firmware

Security researchers found three surveillance implants in ZBT Routers firmware. The CVE- 2026- 66747 flaw allows remote root access on models like the Z8102AX.

ZBT Routers CVE-2026-66747: Three Surveillance Implants Found in Firmware

Security researchers have uncovered three distinct surveillance implants hidden in the firmware of routers manufactured by Shenzhen Zhibotong Electronics. These hidden components allow attackers to gain remote root access and exfiltrate sensitive data from affected devices. The discovery matters to anyone using these routers because the implants operate silently in the background, bypassing standard security measures. Users rely on these devices for network connectivity, and compromised firmware turns that trust into a direct vulnerability.

VulnCheck identifies critical backdoors in ZBT hardware sold under multiple brands

The affected hardware includes models such as the Z8102AX, WG3526, WE826-T3-DSIM, and ZBT-WE826-T2. ZBT sells these units under various white-label brands like Deep Orange, WiFlyer, and KuWFi, which means the issue extends beyond just one brand name. Security firm VulnCheck identified the implants and assigned the primary vulnerability the identifier CVE-2026-66747. The flaw carries a CVSS score of 9.3, indicating a critical severity level that demands immediate attention from network administrators.

ZBT router model Z8102AX showing network ports and status LEDs

The first implant, named ENDLESSDOORS, disguises itself as a kernel process while phoning home to a command server without any authentication. The second component, DARKLANTERN, opens a listener on WAN UDP port 9992 to accept remote commands without requiring user credentials. The third implant, SPEAKINGSTONE, beacons outbound to ZBT infrastructure to steal PPPoE credentials and enable DNS hijacking. Together, these tools provide a comprehensive backdoor for remote control and data theft.

Sinkhole analysis conducted by researchers revealed approximately 390 infected devices, with the majority located in China and connected to China Mobile networks. ZBT has described the ENDLESSDOORS component as a legitimate after-sales technical support mechanism, a claim that contradicts the security findings. The presence of unauthenticated remote access in all three implants suggests a design flaw that goes beyond simple maintenance tools. Network owners should verify their router firmware status to ensure they are not part of the compromised group.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion