CVE-2026-74233
9.8Zbtlink · WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, WE2426-C, WE5926-EC_QP, WF3526-P, CTN720-W1, LF-1541, MT7620N, WRC1
Multiple Zbtlink router models contain an unauthenticated command injection vulnerability in the infosrvd service via UDP port 9992, allowing remote code execution as root.
Executive summary
A critical unauthenticated command injection vulnerability in Zbtlink router firmware allows remote attackers to execute arbitrary code as root, posing a severe risk of full device compromise.
Vulnerability
The flaw exists in the infosrvd service (UDP/9992) where hardcoded cryptographic keys and a wildcard MAC bypass mechanism fail to authenticate remote requests, enabling unauthenticated OS command injection.
Business impact
Successful exploitation grants a remote, unauthenticated attacker complete control over the affected hardware with root-level privileges. This enables total system compromise, including the ability to intercept network traffic, pivot into internal environments, or deploy persistent malware, justifying the 9.8 CVSS critical severity score.
Remediation
Immediate Action: Identify all exposed Zbtlink devices and isolate them from the public internet immediately, as no patch availability is confirmed for these legacy models.
Proactive Monitoring: Monitor network traffic for unusual UDP activity on port 9992 and inspect device logs for unexpected command execution or configuration changes.
Compensating Controls: Implement strict firewall rules to block all inbound traffic to UDP port 9992 from untrusted networks until firmware updates are applied or devices are retired.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the VulnCheck technical write-up.
Analyst recommendation
Given the critical nature of this vulnerability and the ease of exploitation, organizations must treat affected Zbtlink routers as compromised if exposed to the internet. Immediate isolation or replacement of these devices is required to prevent unauthorized access and potential lateral movement within the network.
More Zbtlink CVEs
Sources
Originally found and disclosed by Jacob Baines of VulnCheck, per the CVE Program record.
- VulnCheck Blog Exploit / PoC
- Third-party advisory