Sceawere
Vulnerability Detail
CVE-2026-74232UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zbtlink Backdoor Remote Command Execution
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- Zbtlink
- Product
- L3_V2_8
- Attack Type
- Embedded Malicious Code
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-27T13:18:33.917Z",
"pubdate": "2026-08-27T13:18:33.917Z",
"executiveSummary": "Multiple Zbtlink and MoreQuick router models contain a critical security vulnerability involving a hardcoded command-and-control (C2) implant known as 'yunmgrd'. This implant facilitates unauthorized remote management and arbitrary command execution with root privileges.\nThe vulnerability resides in a cleartext, unauthenticated UDP communication channel used by the implant to beacon to a hardcoded C2 server. By intercepting or hijacking this network path, a remote unauthenticated attacker can masquerade as the legitimate C2 server and inject arbitrary commands into the affected devices.\nImpacted devices include various firmware versions for Zbtlink L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, and several MoreQuick models including MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, MQAP-7628, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10.\nThe risk is severe, as the vulnerability allows for full system compromise. An attacker can exfiltrate sensitive information, such as PPPoE credentials, manipulate network traffic via DNS modification, or establish persistent backdoors through reverse SSH tunnels. Exploitation does not require prior authentication, making these devices highly susceptible to network-based attacks.",
"technicalDetails": "The primary security failure is the presence of 'yunmgrd', a hidden daemon that acts as a backdoor implant. This process is designed to communicate with a hardcoded C2 server over a UDP-based protocol. The fundamental architectural flaw is that this communication occurs over an unauthenticated, cleartext channel, providing no integrity checks or encryption for the transmitted commands.\nThe vulnerability is exposed to any attacker capable of positioning themselves within the network path between the router and the hardcoded C2 destination. This network exposure allows for Man-in-the-Middle (MitM) attacks where the attacker can intercept, modify, or spoof the UDP traffic. Because the 'yunmgrd' process runs with root privileges, any command successfully injected via this channel is executed with the highest level of system authority.\nExploitation follows a specific flow: 1) The attacker monitors outbound UDP traffic to identify the C2 beacon. 2) The attacker hijacks the connection, either by spoofing the C2 server response or by intercepting the session. 3) By responding with malicious payloads encapsulated in the expected UDP protocol format, the attacker commands the 'yunmgrd' process to execute arbitrary shell commands. 4) Given the root-level execution environment, the attacker gains full control over the underlying Linux-based operating system.\nThe post-exploitation phase allows for significant device manipulation. Attackers can modify system DNS configuration to redirect user traffic for phishing or credential theft. The exfiltration of stored PPPoE credentials grants the attacker deeper access to the ISP-provided network services. Furthermore, the ability to initiate reverse SSH tunnels provides the attacker with a persistent, encrypted, and authenticated remote access mechanism, bypassing traditional perimeter defenses that might block incoming connections. This mechanism remains active even if the primary UDP C2 channel is closed or if the network topology changes, effectively hardening the attacker's presence on the compromised device. Because these devices serve as gateways, the compromise effectively undermines the security of the entire local area network connected to them."
}