Security experts reveal longstanding backdoors in ZBT-based routers, dating back to 2019, exposing devices worldwide to remote control, credential theft, and DNS hijacking, prompting calls for urgent device reassessment.
Security researchers have identified two backdoors in ZBT-based white-label routers that can let an attacker reach devices from the public internet, steal PPPoE credentials, alter DNS settings and create reverse SSH tunnels. According to VulnCheck, the implants, named DARKLANTERN and SPEAKINGSTONE, have been present in firmware dating back to 2019 and affect hardware sold under multiple brand names in different markets.
DARKLANTERN is the more direct of the two. VulnCheck says it listens on UDP port 9992 and, in many deployments, the firewall leaves that service exposed from the WAN. A simple probe can disclose device details such as the model, firmware, MAC address, SSID and IP address. From there, a command type marked 0x17 can write to a system file and execute attacker-supplied shell commands as root, giving full control of the router.
SPEAKINGSTONE takes a different route. VulnCheck says the router daemon reaches out over UDP port 10000 to a hard-coded command-and-control domain, and the protocol allows unauthenticated execution, credential retrieval and DNS manipulation. Because the traffic is plain text, an attacker positioned on the network path could impersonate the legitimate controller and hijack the device. VulnCheck also said a sinkholed backup domain exposed 392 devices, most of them in China.
The broader issue is not limited to one model name. The same hardware is sold worldwide as white-label equipment, which makes brand-based inventory weak protection against supply-chain risk. For network teams, the warning signs include unexpected traffic to UDP 9992 or outbound UDP 10000, DNS changes, reverse SSH activity and unexplained PPPoE access. The practical response is to identify affected boards and firmware, isolate or replace untrusted devices, and block unnecessary WAN and egress traffic where possible.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





