China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Summary

Shenzhen Zhibotong Electronics (ZBT) routers have been found to contain two undocumented factory implants in their firmware. These implants, SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to gain root access and execute commands on the devices.

IFF Assessment

FOE

The discovery of pre-installed implants granting unauthenticated root access represents a significant vulnerability that attackers can exploit.

Severity

9.8 Critical

Defender Context

This discovery highlights the importance of supply chain security and thoroughly vetting hardware from all manufacturers, especially those with potential geopolitical ties. Defenders should prioritize inspecting network devices for such pre-installed backdoors and consider implementing strict network segmentation to limit the blast radius of compromised devices.

Read Full Story →