CuraSec

Plan active

ZBT Routers Ship With Two Factory Implants Granting Unauthenticated Root

2026-08-28 21:21 UTC · The Hacker News · read the source ↗ #supply-chain#router-firmware#hardware-backdoor
  • Engineer — Plan: ZBT is a niche brand unlikely in most enterprise estates, but the factory-implant nature and public PoCs on both CVEs elevate urgency if these devices are deployed; audit hardware inventory for any ZBT devices and replace or network-isolate them pending vendor response.
  • SOC/IR — Plan: If ZBT routers appear anywhere in the estate, treat them as pre-compromised and hunt for anomalous outbound traffic or unexpected management-plane connections; also worth adding device-model detection logic for SPEAKINGSTONE/DARKLANTERN C2 patterns if VulnCheck publishes IOCs.
  • Leader — Learn: A confirmed hardware supply-chain backdoor from a Chinese OEM reinforces the policy case for approved-hardware lists and firmware provenance requirements; useful context for board-level discussions on hardware procurement risk, though ZBT’s limited enterprise footprint makes immediate action unlikely for most organizations.
  • Signals: CVE-2026-74232 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub · CVE-2026-74233 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.