Zbtlink MQWrt yunmgrd Cloud C2 Implant
Summary
| CVE | CVE-2026-74232 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-27 13:18:33 UTC |
| Updated | 2026-08-27 17:19:51 UTC |
| Description | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels. |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-300 | CWE-506 | CWE-506 Embedded Malicious Code | CWE-300 Channel Accessible by Non-Endpoint
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Zbtlink | L3 V2 8 | affected 3.0.0.4.528 custom | Not specified |
| CNA | Zbtlink | WE826-T2 | affected 19.1101 custom | Not specified |
| CNA | Zbtlink | ZBT-7628 | affected 1.0.0.2.007 custom | Not specified |
| CNA | Zbtlink | ZBT-ZBT7621 | affected 1.0.0.3.001 custom | Not specified |
| CNA | MoreQuick | MQAC-7620 | affected 1.0.0.2.000 custom | Not specified |
| CNA | MoreQuick | MQAC-7620A | affected 1.0.0.2.000 custom | Not specified |
| CNA | MoreQuick | MQAP-7620 | affected 1.0.0.2.000 custom | Not specified |
| CNA | MoreQuick | MQAP-7620A | affected 1.0.0.2.000 custom | Not specified |
| CNA | MoreQuick | MQAP-7628 | affected 1.0.0.2.000 custom | Not specified |
| CNA | Unknown | AP522 | affected 1.0.0.2.014 custom | Not specified |
| CNA | Unknown | AP7628 | affected 3.0.0.4.380 custom | Not specified |
| CNA | Unknown | APG721B | affected 19.0809 custom | Not specified |
| CNA | Unknown | HC5661A | affected 3.0.0.4.380 custom | Not specified |
| CNA | Unknown | HK300 | affected 1.0.0.2.032 custom | Not specified |
| CNA | Unknown | MAP-N10 | affected 1.0.0.2.044 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.vulncheck.com/advisories/zbtlink-mqwrt-yunmgrd-cloud-c2-implant | [email protected] | www.vulncheck.com | |
| vulncheck.com/blog/zbt-darklantern-speakingstone | [email protected] | vulncheck.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jacob Baines of VulnCheck (en)
There are currently no legacy QID mappings associated with this CVE.