SPEAKINGSTONE factory implant in ZBT router firmware
SPEAKINGSTONE is an undocumented factory-installed implant in ZBT router firmware granting unauthenticated remote root command execution. Disclosed by VulnCheck alongside CVE-2026-74233. CVSS 9.8.
- Vendor
- Shenzhen Zhibotong Electronics
- Product
- ZBT routers
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.5%
- Status
- unpatched
- Published
CVE-2026-74232 tracks SPEAKINGSTONE, one of two factory-installed implants discovered by VulnCheck’s zero-day research team in firmware shipped by Shenzhen Zhibotong Electronics (ZBT). The implant allows an unauthenticated remote attacker to execute arbitrary commands with root privileges.
SPEAKINGSTONE is a distinct attack path from its companion implant, DARKLANTERN (CVE-2026-74233). Both are present in ZBT router firmware as shipped and do not require any post-manufacture compromise to be present on a device.
No patch was available at time of disclosure. Network operators running ZBT hardware should isolate affected devices and monitor VulnCheck and ZBT’s official advisory channels for firmware updates addressing both implants.
