Overview
- VulnCheck disclosed two factory‑installed implants called SPEAKINGSTONE and DARKLANTERN on Friday and assigned them CVE‑2026‑74232 and CVE‑2026‑74233 with high severity scores.
- DARKLANTERN runs as infosrvd and opens a WAN listener on UDP/9992 that accepts unauthenticated probes and can append and execute shell commands as root.
- SPEAKINGSTONE runs as yunmgrd and beacons outbound on UDP/10000 to a hardcoded command server, allowing remote command execution, PPPoE credential theft, DNS changes, and reverse SSH tunnels.
- Internet scans and a sinkhole show hundreds of reachable devices with 203 DARKLANTERN responders across 22 countries and 392 devices beaconing to a SPEAKINGSTONE backup domain, with most beaconing devices located in China on China Mobile.
- Researchers published IoCs, Suricata and YARA rules, and concrete mitigations including blocking inbound UDP/9992, restricting outbound UDP/10000, inventorying models by board ID or MAC OUI, and isolating or replacing affected routers while vendor fixes remain unavailable.