View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

VulnCheck Finds Two Surveillance Implants in ZBT Router Firmware

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • VulnCheck Finds Two Surveillance Implants in ZBT Router Firmware
    VulnCheck found two factory surveillance implants in ZBT router firmware.
    • Affected products are ZBT/Zbtlink and white-labeled routers, including WE826-T2, WE826-Q, WE1326, WE357, WE5926, WG108, WG3526, L3_V2_8, ZBT-7628 and multiple MoreQuick and AP models.
    • SPEAKINGSTONE (CVE-2026-74232) affects builds including WE826-T2 19.1101, L3_V2_8 3.0.0.4.528, ZBT-7628 1.0.0.2.007 and MoreQuick MQAC/MQAP 1.0.0.2.000.
    • DARKLANTERN (CVE-2026-74233) runs as infosrvd on UDP 9992 and enables unauthenticated root command execution through ineffective authentication.
    • SPEAKINGSTONE runs as yunmgrd, phones home over UDP 10000, executes root commands, exfiltrates WAN PPPoE credentials, modifies DNS hijack lists and opens reverse SSH tunnels.
    • Indicators include ac-link[.]com, findmyipaddr[.]com, 47.107.224[.]89, and services or files named infosrvd, yunmgrd, inetdetect, /etc/exec/cmd and /tmp/yunclient.conf.
      ๐Ÿ“„ Source: vulncheck.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-82456 โ€” CVSS 10.0 โ€” argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTPargocd-mcp 0.8...

  • CVE-2026-82466 โ€” CVSS 9.4 โ€” Rodauth before 2.46.0 Authentication Bypass via webauthn_loginRodauth before ...

  • CVE-2026-82473 โ€” CVSS 8.8 โ€” KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoin...

  • CVE-2026-82450 โ€” CVSS 8.7 โ€” BookStack RCE via ZIP Import Polyglot (CVE-2026-82450)

  • CVE-2026-82463 โ€” CVSS 8.6 โ€” pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Checkp...

  • CVE-2026-82461 โ€” CVSS 8.6 โ€” pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access T...

  • CVE-2026-82474 โ€” CVSS 8.5 โ€” Sudo through 1.9.17p2 Intercept Policy Bypass via execveatSudo through 1.9.17...

  • CVE-2026-56854 โ€” CVSS 7.5 โ€” Source-address critical option not enforced for non-public-key auth callbacks...

  • CVE-2026-82465 โ€” CVSS 6.9 โ€” pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequestpac4j-s...

  • CVE-2026-82462 โ€” CVSS 6.9 โ€” pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitutionpa...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check