🖥️
Hardware 📅 2026-08-28 · 03:17 PM IST ⏱ 2 min read

Factory-Installed Router Backdoors Give Hackers Complete Server Access

Two hidden security flaws discovered in ZBT routers allow attackers to seize full control without needing passwords.

Researchers at VulnCheck have uncovered a serious problem affecting routers manufactured by Shenzhen Zhibotong Electronics. The company's devices were shipped from the factory with two separate hidden security weaknesses built directly into the firmware—the software that runs the hardware. Security experts have named these vulnerabilities SPEAKINGSTONE and DARKLANTE.

The dangerous part: anyone on the internet can exploit these flaws without needing a password, username, or any legitimate access to your network. Once inside, attackers gain complete administrative power over the router, essentially becoming the device's owner.

What This Means

Think of your router like the security guard at your office building's front door. If that guard has a hidden backdoor that anyone can walk through, suddenly every room in the building is accessible. That's what these factory-installed weaknesses do—they bypass all normal security protections.

For web hosting companies and data centers that use these routers, the implications are severe. A single malicious person could potentially:

The fact that these flaws were intentionally placed during manufacturing—rather than being accidental bugs—raises serious concerns about the device's trustworthiness.

Why You Should Care

If you operate a website, run an online business, or host applications with a provider using these routers, your data could be at serious risk. Small businesses that use cheap networking equipment from less-known manufacturers are particularly vulnerable because they often lack advanced security monitoring.

This incident illustrates a growing problem in technology: supply chain security. When manufacturers include hidden access points in their products, no amount of software updates or security patches can fully protect you. It's like discovering your car's locks were designed to have a master key you don't control.

Even if you don't directly use ZBT routers, this discovery reminds us that threats don't always come from hackers attacking from outside—sometimes they're built in from day one.

What You Can Do

If you manage network infrastructure: Check your equipment inventory immediately to identify whether you're using any routers from this manufacturer. Contact your provider about replacement options or firmware patches if they become available.

For everyday users: Review what routers your internet service provider has installed. If you don't recognize the brand, research it or request equipment from a more established manufacturer.

General best practices:

This discovery underscores why technology purchasing decisions matter—the cheapest option often carries hidden costs in security and trustworthiness.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →