Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Cyber Group Finds Surveillance Backdoors in Chinese Routers Sold in US
Epoch Times ^ | 08/31/2026 | Arthur Zhang

Posted on 08/31/2026 8:28:06 PM PDT by SeekAndFind

Cybersecurity researchers have found surveillance backdoors in Chinese carrier routers made by Zbtlink and the same software in a different Zbtlink-made router sold through Amazon.

Chinese law requires telecom and internet companies to provide technical assistance to police and state-security agencies.

In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.

The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.

The researchers then found both programs operating on routers already connected to the internet.

The findings expand VulnCheck’s Aug. 5 investigation, which involved a different Zbtlink backdoor, named ENDLESSDOORS, found across more than 20 router models sold worldwide.

The newly discovered backdoors are older. VulnCheck found them in router software dating to 2019, years before ENDLESSDOORS was disclosed.

Speakingstone was not simply dormant code sitting inside old router software. It was still running.

VulnCheck researcher Jacob Baines registered an abandoned internet address that Speakingstone had been programmed to contact. Routers began sending information to it almost immediately, according to VulnCheck.

By Aug. 21, 392 routers had contacted the researchers. Of those, 390 were in China, and 83 percent were connected through China Mobile. Another 304 used Wi-Fi names beginning with “CMCC,” China Mobile’s commonly used abbreviation. Baines also detailed the figures in an Aug. 27 post on X.

Most—363 of the 392 routers—were the same model running the same software version.

Baines said the pattern appeared to be a large deployment of routers provided by a telecommunications carrier to customers inside China. VulnCheck described it as “domestic Chinese surveillance technology.”

The 392 routers may represent only part of the deployment. VulnCheck counted devices trying to reach the abandoned backup address; routers already communicating with the main server would not have appeared in that count, Baines explained.

Backdoor Could Redirect Traffic, Steal Credentials

Speakingstone gave whoever controlled its remote server broad access to an affected router.

VulnCheck said an operator could collect information about the device, obtain the credentials it used to connect to the internet, redirect internet traffic, and take control of the router. Its security advisory also says the software can open another path for remote access.

Baines described Speakingstone in his Aug. 27 post as software that “phones home to ZBT infrastructure and supports remote surveillance.” ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.

The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.

Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.

Jeremiah Ford, a senior cloud support engineer with 25 years of experience in information technology, said the most serious issue was that the routers exposed administrator-level access directly to the public internet.

“This is the biggest problem,” Ford said.

He said full control of a router could also give an attacker access to other devices on the same network. Ford called the scale of the exposure significant, pointing to VulnCheck’s finding that every detected Darklantern device offered administrator-level access without authentication.

“This is huge,” he said. “And based on the numbers of devices affected by this, the scale could have been huge, if it went undetected.”

The U.S. exposure extended beyond the single router the researchers bought on Amazon.

VulnCheck found 203 routers running Darklantern that were directly reachable from the internet across 22 countries. More than half—103—were in the United States. The devices identified themselves as 16 different ZBT router models.

Zbtlink Sold Under Other Brands

The same Speakingstone software found on the China Mobile-linked routers was present in the Deep Orange router VulnCheck bought through Amazon in the United States.

The researchers traced the device to Zbtlink. That device also contained Darklantern.

Zbtlink manufactures equipment that other companies can sell under different names, meaning buyers may not see the Zbtlink name on the product.

VulnCheck traced Zbtlink hardware to brands and products sold in multiple countries, including the United States, but cautioned that not every product using Zbtlink hardware necessarily contains the backdoors.

The discovery comes in a country where telecom and internet companies are legally required to assist police and state-security agencies.

China’s Cybersecurity Law requires network operators to provide technical support and assistance for national-security work and criminal investigations.

Article 18 of China’s Counter-Terrorism Law requires telecommunications and internet providers to give public-security and state-security agencies technical interfaces, decryption, and other technical assistance for terrorism investigations.

Accounts of police access to telecommunications systems date back decades.

Minghui, a U.S.-based website that documents the persecution of Falun Gong practitioners and publishes first-hand accounts from China, has documented cases in which practitioners were detained after authorities monitored their telephone or internet communications.

In a 2006 article, Minghui described special police-monitoring interfaces connecting Chinese telecommunications equipment with public-security systems. The account said police could use the systems to trace calls and identify people contacted by someone under surveillance.

The article concerned an earlier generation of telecommunications equipment, two decades before the newly reported Zbtlink backdoors.

US Takes Action

The findings were issued months after the Federal Communications Commission (FCC) moved to restrict approval of new foreign-made consumer routers over national security concerns.

On March 23, the FCC added foreign-produced consumer-grade routers to its Covered List following a national security determination by executive branch agencies. The action prevents approval of new covered router models unless an exemption applies; equipment already authorized can remain on the market.

The FCC said malicious actors had exploited weaknesses in foreign-made routers to attack U.S. households, enable espionage, and disrupt networks. It also said foreign-made routers were involved in the Volt Typhoon, Flax Typhoon, and Salt Typhoon cyber campaigns targeting U.S. infrastructure.

As of Aug. 28, VulnCheck’s advisories did not list patched software versions for Speakingstone or Darklantern, leaving owners of affected routers without a published fix.


TOPICS: China; Foreign Affairs; News/Current Events
KEYWORDS: arthurzhang; ccp; chicoms; china; chinatruth; cybersecurity; routers

Click here: to donate by Credit Card

Or here: to donate by PayPal

Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794

Thank you very much and God bless you.


1 posted on 08/31/2026 8:28:06 PM PDT by SeekAndFind
[ Post Reply | Private Reply | View Replies]

To: SeekAndFind

This has been a known issue for over a decade.

“Refurbished” Cisco gear is notorious for it.

L


2 posted on 08/31/2026 8:35:03 PM PDT by Lurker ( Peaceful coexistence with the Left is not possible. Stop pretending that it is.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind

How do I know if I have a Chicom router? Is there a list somewhere?


3 posted on 08/31/2026 8:43:59 PM PDT by VanShuyten ("...that all the donkeys were dead. I know nothing as to the fate of the less valuable animals. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind

IT found a Cisco card trying to phone home - didn’t work, network was air-gapped.

Got a spare machine laying around - thinking OpenBSD router or replace my current TP-Link router. It’s an older unit.


4 posted on 08/31/2026 8:51:09 PM PDT by dagunk
[ Post Reply | Private Reply | To 1 | View Replies]

To: VanShuyten

How do I know if I have a Chicom router? Is there a list somewhere?

Check the tag with the serial number/password/ssid on it.


5 posted on 08/31/2026 8:52:43 PM PDT by dagunk
[ Post Reply | Private Reply | To 3 | View Replies]

To: wattojawa; Carriage Hill

Ping.


6 posted on 08/31/2026 8:53:48 PM PDT by lightman (Beat the Philly fraud machine the Amish did onest, ja? Nein, zweimal they did already!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind

Switch to Starlink - no worries.


7 posted on 08/31/2026 9:04:44 PM PDT by Spacetrucker
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spacetrucker

Switch to Starlink - no worries.

****************************

Got a nephew on Starlink. He’s very satisfied with his hookup.


8 posted on 08/31/2026 9:24:36 PM PDT by dagunk
[ Post Reply | Private Reply | To 7 | View Replies]

To: SeekAndFind

Remember, any Chinese company of any size, and most certainly in tech, for export - has a required Communist Party apparatus and Party head within it.


9 posted on 08/31/2026 9:46:47 PM PDT by PGR88
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind
Don’t totally trust anything. Get an off-the-shelf router model supported by OpenWRT and immediately replace its firmware with that, even if its factory firmware is itself a version of OpenWRT, like Zbtlink or its clones use. They could have a PLA-modified version. Otherwise, hope for the best with your provider’s Wi-Fi router or go with Starlink and only use its Wi-Fi router, that’s the safest bet.

Chances are you’re still ok if you only go to sites starting with “https”—until the Chinese figure out how to quickly decode encrypted traffic that gets copied and forwarded to the China mothership. But they could still take over the router with their hacked factory firmware and at least cut you off if they wanted to…. It’s a jungle out there!

10 posted on 08/31/2026 10:09:23 PM PDT by mikey_hates_everything
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson