Particle.news

Factory Implants in Chinese-Made Routers Give Remote Root Access

The disclosure includes CVE assignments, sinkhole telemetry and mitigation guidance requiring immediate network filtering and device inventories.

Overview

  • VulnCheck disclosed two factory‑installed implants called SPEAKINGSTONE and DARKLANTERN on Friday and assigned them CVE‑2026‑74232 and CVE‑2026‑74233 with high severity scores.
  • DARKLANTERN runs as infosrvd and opens a WAN listener on UDP/9992 that accepts unauthenticated probes and can append and execute shell commands as root.
  • SPEAKINGSTONE runs as yunmgrd and beacons outbound on UDP/10000 to a hardcoded command server, allowing remote command execution, PPPoE credential theft, DNS changes, and reverse SSH tunnels.
  • Internet scans and a sinkhole show hundreds of reachable devices with 203 DARKLANTERN responders across 22 countries and 392 devices beaconing to a SPEAKINGSTONE backup domain, with most beaconing devices located in China on China Mobile.
  • Researchers published IoCs, Suricata and YARA rules, and concrete mitigations including blocking inbound UDP/9992, restricting outbound UDP/10000, inventorying models by board ID or MAC OUI, and isolating or replacing affected routers while vendor fixes remain unavailable.