Multiple Zbtlink and MoreQuick router firmware versions ship with a pre-installed backdoor C2 implant called 'yunmgrd' that communicates over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack this channel and execute arbitrary commands as root on affected devices. The vulnerability affects a wide range of devices including Zbtlink L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, MoreQuick MQAC/MQAP series, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10. Beyond remote code execution, the attacker can modify DNS entries, exfiltrate PPPoE credentials, and establish reverse SSH tunnels for persistent access. This is effectively a supply-chain-level backdoor shipped in production firmware, posing severe risks to network infrastructure and connected environments. The issue was reported by VulnCheck under the campaign name 'DarkLantern/SpeakingStone'.
yunmgrd