Two CVSS 9.8 vulnerabilities in Zbtlink router and access-point firmware — CVE-2026-74233 and CVE-2026-74232 — were disclosed together by VulnCheck’s own research team and reported exploited, both dated added to VulnCheck’s KEV catalog on August 27, 2026. Both allow unauthenticated remote command execution as root against a wide range of Zbtlink-manufactured firmware sold under Zbtlink’s own name and rebranded through several third-party model lines.
Both exploitation reports are single-sourced. CISA has not added either CVE to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing for either CVE.
Two distinct bugs, one disclosure, one manufacturer
VulnCheck’s own research — cited by NVD for both records — frames these as part of the same disclosure effort against Zbtlink’s product line, though the two CVEs are structurally different vulnerabilities rather than two instances of the same bug:
CVE-2026-74233 (CWE-78, OS Command Injection) is a command injection in the infosrvd service listening on UDP port 9992. NVD’s description states the service’s authentication mechanism uses a hardcoded salt and an “all-zero wildcard MAC bypass” that renders the authentication check ineffective — a remote unauthenticated attacker can send a single crafted UDP packet to execute arbitrary commands as root. This CVE affects Zbtlink’s WE1326, WE357, WE5926, WE826, WG108, WG3526, WE2426-C, and WE5926-EC_QP model lines, plus CTN720-W1, LF-1541, MT7620N, and WRC1.
CVE-2026-74232 (CWE-300 / CWE-506, Channel Accessible by Non-Endpoint plus a hardcoded backdoor mechanism) describes a different weakness: an implant called yunmgrd shipped in the firmware itself, reachable over an unauthenticated cleartext UDP channel to a hardcoded command-and-control server. NVD states this allows a remote attacker on the network path to hijack the channel, execute arbitrary root commands, modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels. This one affects a different, broader firmware set — Zbtlink’s L3_V2_8, WE826-T2, ZBT-7628, and ZBT-ZBT7621 lines, plus OEM rebrands sold as MoreQuick MQAC-7620/MQAP-7620/MQAP-7628, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10.
The practical distinction: CVE-2026-74233 is a conventional (if severe) authentication-bypass command-injection bug in a network daemon. CVE-2026-74232 describes firmware that ships with backdoor connectivity to an external server built in — a materially different risk category, since it does not require an attacker to discover or exploit anything beyond reaching the implant’s listening channel.
Evidence and confidence
- Medium confidence — for both CVEs, the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE classification, and the affected-model lists all trace to NVD alone. The exploitation reports trace to VulnCheck KEV alone. - Unknown-leaning — exploitation probability. FIRST’s EPSS model scores CVE-2026-74233 at 0.02633 (84.8th percentile) and CVE-2026-74232 at 0.00474 (39.9th percentile) as of our ingestion — a meaningful gap between the two that is worth noting even though both carry the same CVSS score and the same VulnCheck exploitation report.
No field is in conflict between our two sources for either CVE. Our data carries no fixed-version field for either CVE, and NVD’s own description does not name a remediated firmware version — consistent with hardware where the manufacturer may not have shipped a patch by the time of disclosure.
Why this matters
Consumer and small-business router firmware from lesser-known manufacturers routinely gets rebranded and resold under a dozen different model names, which is exactly the pattern both CVEs show — a single vulnerable firmware base reaching the market as Zbtlink-branded hardware and under at least seven other brand names. A device owner has no way to know their router is affected without checking the specific firmware version against NVD’s model list, because the box in front of them may say “MoreQuick” or “AP522” with no visible connection to Zbtlink.
CVE-2026-74232’s built-in backdoor implant is the more structurally troubling of the two: it does not describe a bug an attacker discovered, but connectivity to an external server that the firmware ships with by design. Absent a vendor-issued patch, the only reliable mitigation for either CVE is removing the affected device from the network or placing it behind a firewall that blocks the described channels — UDP 9992 for CVE-2026-74233, and outbound connectivity to the hardcoded C2 endpoint for CVE-2026-74232, per NVD’s descriptions.
Frequently Asked Questions
What is CVE-2026-74233?
A CVSS 9.8 OS command injection vulnerability (CWE-78) in the infosrvd service (UDP/9992) on multiple Zbtlink router and access-point firmware lines, allowing unauthenticated root command execution via a crafted UDP packet.
What is CVE-2026-74232?
A CVSS 9.8 vulnerability (CWE-300/CWE-506) describing a hardcoded backdoor implant (yunmgrd) shipped in a different set of Zbtlink firmware, reachable over unauthenticated cleartext UDP to a hardcoded command-and-control server.
Are these being actively exploited? VulnCheck’s KEV feed reports both exploited, dated August 27, 2026. Both reports are single-sourced; CISA has not listed either CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
Is my router affected if it isn’t sold under the Zbtlink brand? Possibly. NVD’s descriptions list specific rebrand model numbers for each CVE — MoreQuick, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10 for CVE-2026-74232’s affected firmware set. Check your device’s exact firmware version against NVD’s published model lists rather than relying on the brand printed on the case.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and neither CVE is CISA-listed.
Is there a firmware update that fixes these? Our data carries no fixed-version information for either CVE, and NVD’s descriptions do not name a remediated release. Check directly with the specific brand’s support channel for your device model.
Severity, vectors, weakness classifications, and affected-model lists sourced from the National Vulnerability Database records for CVE-2026-74233 and CVE-2026-74232, both of which cite VulnCheck’s own disclosure research. Exploitation status and the August 27, 2026 catalog date for both CVEs are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. Neither CVE is listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS scores and percentiles from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.