← Back to overview

Multiple Zbtlink router firmware versions contain a critical unauthenticated command injection vulnerability in the infosrvd service listening on UDP port 9992. A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root on affected devices. The vulnerability is exacerbated by a broken authentication mechanism that uses a hardcoded salt and an all-zero wildcard MAC address bypass, making the authentication completely ineffective. Affected devices include Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, WE2426-C, WE5926-EC_QP, WF3526-P, CTN720-W1, LF-1541, MT7620N, and WRC1 across various firmware versions. The vulnerability is tracked as CVE-2026-74233 and has been documented by VulnCheck, who published a detailed advisory and blog post. Given the root-level code execution capability and lack of authentication required, this vulnerability poses a critical risk to any exposed device.

Affected products

  • CTN720-W1 firmware 19.1101
  • LF-1541 firmware 19.1101
  • MT7620N firmware 19.1101
  • WRC1 firmware 20.0622
  • Zbtlink WE1326 firmware 19.1101
  • Zbtlink WE2426-C firmware 19.1112
  • Zbtlink WE357 firmware 19.1101
  • Zbtlink WE5926 firmware 19.1101
  • Zbtlink WE5926-EC_QP firmware 20.0516
  • Zbtlink WE5926-WD firmware 19.1101
  • Zbtlink WE826-Q firmware 19.1101
  • Zbtlink WE826-T2 firmware 19.1101
  • Zbtlink WE826-WD firmware 19.1101
  • Zbtlink WF3526-P firmware 19.051
  • Zbtlink WG108 firmware 19.1101
  • Zbtlink WG3526 firmware 19.1101

Related CVE's

  • CVE-2026-74233

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities