CVE-2026-74233
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zbtlink | WE1326 | 19.1101 | affected |
| Zbtlink | WE2426-C | 19.1112 | affected |
| Zbtlink | WE357 | 19.1101 | affected |
| Zbtlink | WE5926 | 19.1101 | affected |
| Zbtlink | WE5926-EC_QP | 20.0516 | affected |
| Zbtlink | WE5926-WD | 19.1101 | affected |
| Zbtlink | WE826-Q | 19.1101 | affected |
| Zbtlink | WE826-T2 | 19.1101 | affected |
| Zbtlink | WE826-WD | 19.1101 | affected |
| Zbtlink | WF3526-P | 19.051 | affected |
| Zbtlink | WG108 | 19.1101 | affected |
| Zbtlink | WG3526 | 19.1101 | affected |
| Unknown | CTN720-W1 | 19.1101 | affected |
| Unknown | LF-1541 | 19.1101 | affected |
| Unknown | MT7620N | 19.1101 | affected |
| Unknown | WRC1 | 20.0622 | affected |
Weaknesses
- CWE-321: Use of Hard-coded Cryptographic Key
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: total
References
- http://vulncheck.com/blog/zbt-darklantern-speakingstone
- https://www.vulncheck.com/advisories/zbtlink-mqwrt-infosrvd-command-injection
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.