CVE-2026-74233 PUBLISHED

Zbtlink MQWrt infosrvd Command Injection

Assigner: VulnCheck
Reserved: 14.08.2026 Published: 27.08.2026 Updated: 27.08.2026

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Zbtlink
Product WE1326
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE2426-C
Versions Default: unknown
  • Version 19.1112 is affected
Vendor Zbtlink
Product WE357
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE5926
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE5926-EC_QP
Versions Default: unknown
  • Version 20.0516 is affected
Vendor Zbtlink
Product WE5926-WD
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE826-Q
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE826-T2
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WE826-WD
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WF3526-P
Versions Default: unknown
  • Version 19.051 is affected
Vendor Zbtlink
Product WG108
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Zbtlink
Product WG3526
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Unknown
Product CTN720-W1
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Unknown
Product LF-1541
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Unknown
Product MT7620N
Versions Default: unknown
  • Version 19.1101 is affected
Vendor Unknown
Product WRC1
Versions Default: unknown
  • Version 20.0622 is affected

Credits

  • Jacob Baines of VulnCheck finder

References

Problem Types

  • Use of Hard-coded Cryptographic Key CWE
  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-88 OS Command Injection