Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-74233

DARKLANTERN factory implant in ZBT router firmware

DARKLANTERN is an undocumented factory-installed implant in ZBT router firmware granting unauthenticated remote root command execution. Disclosed by VulnCheck alongside CVE-2026-74232. CVSS 9.8.

cat cve-2026-74233.json
Vendor
Shenzhen Zhibotong Electronics
Product
ZBT routers
CVSS
9.8
EPSS (exploit probability)
2.6%
Status
unpatched
Published

CVE-2026-74233 tracks DARKLANTERN, one of two factory-installed implants discovered by VulnCheck’s zero-day research team in firmware shipped by Shenzhen Zhibotong Electronics (ZBT). Like its companion SPEAKINGSTONE (CVE-2026-74232), DARKLANTERN allows an unauthenticated remote attacker to execute arbitrary commands with root privileges.

The two implants use distinct mechanisms and are assigned separate CVE identifiers, meaning both must be addressed for a device to be considered clean. Neither requires post-manufacture compromise to be present on an affected device.

No patch was available at time of disclosure. Network operators running ZBT hardware should isolate affected devices and monitor VulnCheck and ZBT’s official advisory channels for firmware updates.