Cybersecurity researchers have discovered two additional backdoors among Zbtlink router backdoors in more than a dozen models.
This raises concerns about unauthorized network access, information collection, and potential traffic redirection.
The discovery comes only weeks after the same manufacturer was linked to another hidden component known as ENDLESSDOORS.
The security controversy surrounding Zbtlink routers is getting bigger.
Earlier this month, researchers discovered a backdoor called ENDLESSDOORS in more than 20 models.
Now VulnCheck has identified two additional hidden components, named Darklantern and Speakingstone, related to Zbtlink router backdoors.
That changes the picture considerably.
This is no longer simply a case involving one suspicious firmware component.
Researchers are now examining a broader set of mechanisms capable of providing significant access and information-gathering capabilities.
What Do Darklantern and Speakingstone Do?
According to VulnCheck, the two newly identified backdoors—Zbtlink router backdoors—are embedded in certain Zbtlink router models and can reveal information about the networks where the devices are installed.
Darklantern and Speakingstone are different from ENDLESSDOORS, but they raise the same fundamental concern:
The Tech Spot Editorial Team
components may be providing access that ordinary router users did not explicitly authorize — or may not even know exists.
Speakingstone is particularly concerning.
Researcher Jacob Baines described it as a surveillance implant after discovering that affected routers attempted to contact an unregistered domain.
After registering that domain, the researcher began receiving information from infected routers.
Routers Were Sending Information Outside the Network

This is one of the most concerning elements of the discovery.
According to VulnCheck’s findings, routers containing Speakingstone attempted to communicate with an external domain.
Once the researcher registered the domain, data began arriving from the affected devices.
Most of the routers identified in that experiment were active in China.
That led Baines to suggest that the mechanism may represent domestic surveillance technology deployed inside China while the same functionality is present in products sold internationally.
However, this remains a researcher’s assessment, not proof that Zbtlink deliberately deployed the technology for espionage.
The Risk Goes Beyond the Router
A router is the main gateway between a local network and the internet.
If hidden software gains privileged access to that router, the risk does not necessarily stop with the device itself.
It can potentially affect other systems connected to the same network.
In a home, that could include:
- computers;
- smartphones;
- security cameras;
- smart TVs;
- IoT devices;
- personal servers;
- and other network equipment.
In a business environment, the consequences could be considerably more serious.
A compromised router could become a starting point for mapping a network, gathering information or potentially manipulating traffic.
The Bigger Problem: Zbtlink May Not Be the Name on the Box

This is one of the most important aspects of the discovery.
Zbtlink manufactures devices that can also be sold under other brands through OEM and ODM arrangements.
That means a consumer may never have heard of Zbtlink and could still own a device running its firmware.
Jacob Baines specifically warned about this problem: not knowing the Zbtlink name does not necessarily mean a device was not manufactured by the company.
That makes identifying affected hardware significantly more difficult.
Zbtlink Denies the Allegations

Zbtlink has disputed the researchers’ interpretation.
Company spokesperson Michael Xia said the remote-access capabilities are intended for authorized after-sales maintenance and technical support, and are supposed to be used only with customer authorization.
The company made a similar argument after the earlier ENDLESSDOORS discovery.
Following the initial disclosure, Zbtlink suspended sales of affected models and removed the relevant firmware from its website while promising security updates.
Researchers, however, continue to question why these components were designed with such deep access to the firmware.
ENDLESSDOORS May Have Been Only the Beginning
The earlier ENDLESSDOORS discovery was already serious.
VulnCheck found that more than 20 Zbtlink models contained a firmware component capable of providing privileged access to the router.
The component was enabled in the firmware and capable of communicating with external infrastructure.
The discovery of Darklantern and Speakingstone suggests the underlying problem may be broader than initially understood.
What Should Users Do?

For ordinary users, the first step is to check the router model and firmware version.
If the device is a Zbtlink model or an OEM product using Zbtlink firmware, users should determine whether it is affected and whether a trusted, updated firmware version is available.
For businesses, the situation requires more attention.
Security teams should examine:
- router firmware;
- unusual outbound connections;
- suspicious DNS requests;
- devices communicating with unknown servers;
- and unexpected processes or components within router firmware.
If a device is suspected of being compromised and no verified firmware is available, replacing the hardware may be safer than continuing to rely on software that cannot be fully audited.
TheTechSpot: The Device Everyone Forgets
When cybersecurity is discussed, people usually think about laptops, smartphones and cloud systems.
Routers are often forgotten.
But the router is the gateway.
If an attacker controls that gateway, they do not always need to begin with the victim’s computer.
That is what makes the Zbtlink case so important.
The problem is not simply that researchers discovered a vulnerability.
The bigger issue is that hidden components may be embedded directly inside the software. Additionally, this software controls the device connecting an entire home or business to the internet.
That raises a much bigger question for the hardware industry:
Should consumers be able to know exactly what software is running on the device that connects their entire digital lives to the internet?
As more devices become connected and intelligent, that question will become increasingly important.
Because sometimes the biggest cybersecurity threat isn’t on the screen you use every day — it’s the device connecting that screen to the internet.
