Multiple Zbtlink router firmware versions contain a critical unauthenticated command injection vulnerability in the infosrvd service listening on UDP port 9992. A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root on affected devices. The vulnerability is exacerbated by a broken authentication mechanism that uses a hardcoded salt and an all-zero wildcard MAC address bypass, making the authentication completely ineffective. Affected devices include Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, WE2426-C, WE5926-EC_QP, WF3526-P, CTN720-W1, LF-1541, MT7620N, and WRC1 across various firmware versions. The vulnerability is tracked as CVE-2026-74233 and has been documented by VulnCheck, who published a detailed advisory and blog post. Given the root-level code execution capability and lack of authentication required, this vulnerability poses a critical risk to any exposed device.