Impact
The vulnerability is a hard‑coded command‑and‑control backdoor embedded in the firmware of several Zbtlink and MoreQuick devices. It exposes an unauthenticated UDP channel that the attacker can hijack to issue arbitrary commands with root privileges. The backdoor also allows DNS takeover, credential exfiltration, and the opening of reverse SSH tunnels, enabling persistent lateral movement. The weakness falls under unauthorized network access (CWE‑300) and in‑band network injection (CWE‑506).
Affected Systems
Affected models include Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826‑T2 firmware 19.1101, Zbtlink ZBT‑7628 firmware 1.0.0.2.007, and Zbtlink ZBT‑ZBT7621 firmware 1.0.0.3.001. MoreQuick devices MQAC‑7620, MQAC‑7620A, MQAP‑7620, MQAP‑7620A, and MQAP‑7628 all ship with firmware 1.0.0.2.000. The list also includes AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP‑N10 firmware 1.0.0.2.044, all of which contain the vulnerable backdoor.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and the vulnerability is exploitable by any entity on the same network that can observe or send packets to the UDP channel. No EPSS value is provided, suggesting that recent exploitation data is unavailable, but the lack of a KEV listing does not mitigate the risk of this high‑impact flaw. An attacker with simple network access can hijack the cleartext channel, execute root‑level commands, and perform further compromise activities without authentication or privilege escalation within the device.
OpenCVE Enrichment