China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Summary
Shenzhen Zhibotong Electronics (ZBT) routers have been found to contain two undocumented factory implants in their firmware. These implants, SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to gain root access and execute commands on the devices.
IFF Assessment
The discovery of pre-installed implants granting unauthenticated root access represents a significant vulnerability that attackers can exploit.
Severity
Defender Context
This discovery highlights the importance of supply chain security and thoroughly vetting hardware from all manufacturers, especially those with potential geopolitical ties. Defenders should prioritize inspecting network devices for such pre-installed backdoors and consider implementing strict network segmentation to limit the blast radius of compromised devices.