Vulnerability Description
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- http://vulncheck.com/blog/zbt-darklantern-speakingstone
- https://www.vulncheck.com/advisories/zbtlink-mqwrt-infosrvd-command-injection
FAQ
What is CVE-2026-74233?
CVE-2026-74233 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P fi...
How severe is CVE-2026-74233?
CVE-2026-74233 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-74233?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.