Security firm VulnCheck found three backdoor-like implants in firmware for routers made by Shenzhen Zhibotong Electronics, better known as ZBT, according to Tom's Hardware. The report says the routers are sold globally under multiple brands because ZBT supplies original equipment manufacturer and original design manufacturer customers, making it difficult for buyers to know whether a device is ZBT-derived. The investigation reportedly began with a Zbtlink AX3000 router. VulnCheck found an implant it named ENDLESSDOORS, which Tom's Hardware describes as a firmware-level remote-control mechanism that starts when the router boots, masquerades as the Linux kernel process kworker, and periodically contacts a hard-coded command-and-control server. According to the report, ENDLESSDOORS has no meaningful authentication or encryption and can pass commands from the server directly to a root shell. VulnCheck demonstrated the issue by impersonating the command server and taking over its own test router, showing that control of the command channel could translate into full control of the device. Tom's Hardware reports that VulnCheck found ENDLESSDOORS in firmware for 20 ZBT models, including the Z8102AX, WG3526 and WE826-T3-DSIM, among other cellular routers. VulnCheck assigned the issue CVE-2026-66747 with a Common Vulnerability Scoring System score of 9.3. The investigation then expanded to a white-labeled device. VulnCheck bought an $88 Deep Orange cellular router from a US seller on Amazon and determined that it was actually a ZBT-WE826-T2, according to Tom's Hardware. Its 2019 firmware was too old to contain ENDLESSDOORS, but researchers found two other implants, which they named DARKLANTERN and SPEAKINGSTONE. DARKLANTERN runs as the infosrvd service and listens on the wide-area network via UDP port 9992, according to the report. Tom's Hardware says it accepts commands from the internet without authentication; a fixed 19-byte probe can cause the router to disclose identifying information including model, firmware version, MAC address and uptime. The report says VulnCheck found DARKLANTERN's protections could be bypassed using a static, hard-coded salt and an all-zero MAC address field, allowing remote attackers to forge a packet and execute arbitrary commands as root. VulnCheck scanned the internet and found 203 exposed DARKLANTERN instances in 22 countries across 16 router models, according to Tom's Hardware. SPEAKINGSTONE is described as a different implant that runs as the yunmgrd service and periodically beacons outbound to ZBT's command-and-control infrastructure. Who benefits: Defenders get concrete details in the report, including service names, ports, model families and the CVE reference for ENDLESSDOORS. Teams with accurate hardware inventories are better positioned to identify potentially affected devices. Who's exposed: Owners of ZBT-made or white-labeled ZBT-derived routers are the exposed population described in the report. The clearest measured exposure is DARKLANTERN: VulnCheck reportedly found 203 exposed instances across 22 countries and 16 models.