← Terug naar overzicht

Multiple Zbtlink and MoreQuick router firmware versions ship with a pre-installed backdoor C2 implant called 'yunmgrd' that communicates over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack this channel and execute arbitrary commands as root on affected devices. The vulnerability affects a wide range of devices including Zbtlink L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, MoreQuick MQAC/MQAP series, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10. Beyond remote code execution, the attacker can modify DNS entries, exfiltrate PPPoE credentials, and establish reverse SSH tunnels for persistent access. This is effectively a supply-chain-level backdoor shipped in production firmware, posing severe risks to network infrastructure and connected environments. The issue was reported by VulnCheck under the campaign name 'DarkLantern/SpeakingStone'.

Affected products

  • AP522 firmware 1.0.0.2.014
  • AP7628 firmware 3.0.0.4.380
  • APG721B firmware 19.0809
  • HC5661A firmware 3.0.0.4.380
  • HK300 firmware 1.0.0.2.032
  • MAP-N10 firmware 1.0.0.2.044
  • MoreQuick MQAC-7620 firmware 1.0.0.2.000
  • MoreQuick MQAC-7620A firmware 1.0.0.2.000
  • MoreQuick MQAP-7620 firmware 1.0.0.2.000
  • MoreQuick MQAP-7620A firmware 1.0.0.2.000
  • MoreQuick MQAP-7628 firmware 1.0.0.2.000
  • Zbtlink L3_V2_8 firmware 3.0.0.4.528
  • Zbtlink WE826-T2 firmware 19.1101
  • Zbtlink ZBT-7628 firmware 1.0.0.2.007
  • Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001

Related CVE's

  • CVE-2026-74232

IOC's

yunmgrd

Categories

  • Data Breach & Exfiltration
  • Mobile & IoT
  • Network Infrastructure
  • Ransomware & Malware
  • Supply Chain & Dependencies