← Back to CVE List
Vulnerability Intelligence Report
Zbtlink MQWrt infosrvd Command Injection

CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

Injection No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-321 ↗Use of Hard-coded Cryptographic Key
CWE-78 ↗Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
Zbtlink WE1326 19.1101 (affected)
Zbtlink WE2426-C 19.1112 (affected)
Zbtlink WE357 19.1101 (affected)
Zbtlink WE5926 19.1101 (affected)
Zbtlink WE5926-EC_QP 20.0516 (affected)
Zbtlink WE5926-WD 19.1101 (affected)
Zbtlink WE826-Q 19.1101 (affected)
Zbtlink WE826-T2 19.1101 (affected)
Zbtlink WE826-WD 19.1101 (affected)
Zbtlink WF3526-P 19.051 (affected)
Zbtlink WG108 19.1101 (affected)
Zbtlink WG3526 19.1101 (affected)
Unknown CTN720-W1 19.1101 (affected)
Unknown LF-1541 19.1101 (affected)
Unknown MT7620N 19.1101 (affected)
Unknown WRC1 20.0622 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Injection

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-08-14T18:01:19
Published2026-08-27T10:40:11
Patch Date2026-08-27
Last Updated2026-08-27T13:41:32

LINK COPIED TO CLIPBOARD