CVE-2026-74232
9.8Zbtlink · L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, MQAP-7628, AP522, AP7628, HC5661A, APG721B, HK300, MAP-N10
Multiple Zbtlink and MoreQuick devices contain a hardcoded backdoor command-and-control implant (yunmgrd) that allows unauthenticated remote attackers to execute arbitrary commands as root.
Executive summary
A critical backdoor vulnerability in various Zbtlink and MoreQuick networking devices allows unauthenticated attackers to achieve full root-level remote code execution.
Vulnerability
The firmware includes a malicious command-and-control implant (yunmgrd) that communicates over an unauthenticated, cleartext UDP channel. This allows an attacker on the network path to hijack the communication and execute arbitrary commands with root privileges.
Business impact
Successful exploitation grants an attacker full administrative control over the affected network devices. This enables the compromise of network traffic via DNS modification, the theft of sensitive PPPoE credentials, and the establishment of persistent backdoors via reverse SSH tunnels. Given the CVSS score of 9.8, this vulnerability represents an extreme risk to network integrity and confidentiality.
Remediation
Immediate Action: Disconnect affected devices from the internet immediately if they are exposed, and check the vendor website for available firmware updates that remove the yunmgrd process.
Proactive Monitoring: Monitor network traffic for anomalous UDP communication patterns directed toward unknown or hardcoded external IP addresses associated with the yunmgrd implant.
Compensating Controls: Implement strict ingress and egress filtering at the network perimeter to block unauthorized UDP traffic and prevent communication with suspicious command-and-control servers.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the VulnCheck technical write-up.
Analyst recommendation
This is a critical security failure caused by the intentional inclusion of a backdoor in production firmware. Organizations currently utilizing these devices should prioritize replacing them or applying vendor-supplied patches immediately, as the presence of a hardcoded command-and-control mechanism makes these devices inherently insecure for any enterprise or home network environment.
More Zbtlink CVEs
Sources
Originally found and disclosed by Jacob Baines of VulnCheck, per the CVE Program record.
- VulnCheck Blog Exploit / PoC
- Third-party advisory