The backdoor was in the router before you took it out of the box
An $88 mobile broadband router sold on Amazon as the Deep Orange 3G/4G/LTE turns out to be a rebadged ZBT WE826-T2. In its firmware, built in 2019 and still shipping, VulnCheck found two services nobody ordered.
The research went out on 28 August and names them SPEAKINGSTONE and DARKLANTERN. The first beacons out to a hard-coded command server over UDP port 10000 and waits for instructions: run commands as root, steal the credentials you typed in for your broadband connection, open a tunnel back in, or change the router's DNS so every website your household visits can be quietly redirected. The second sits on UDP port 9992 listening for anyone on the internet who cares to knock, and the router's own firewall is set up to let them through. Its authentication is a fixed key baked into the firmware, which is another way of saying it has none. The two carry CVE-2026-74232 and CVE-2026-74233, rated above 9 out of 10.
What makes this awkward is the badging. ZBT hardware is resold as Wave WiFi, Lippert WiFi On-The-Go, MOFI, Digineo, KuWFi, Cioswi and others across the US, Canada, Australia, Germany and beyond, often in campervans, boats and holiday rentals. ZBT once described an earlier implant found in its firmware as an after-sales support tool. It has said nothing about these two.
There is no patch to wait for, so if one of those names is on the box, the honest answer is to replace it. Most households will not own one, but almost every household owns something on the network they have forgotten about. Tendvane's Network scan lists what is actually answering on your Wi-Fi, and the surprises are usually the point.