Description
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a hard‑coded command‑and‑control backdoor embedded in the firmware of several Zbtlink and MoreQuick devices. It exposes an unauthenticated UDP channel that the attacker can hijack to issue arbitrary commands with root privileges. The backdoor also allows DNS takeover, credential exfiltration, and the opening of reverse SSH tunnels, enabling persistent lateral movement. The weakness falls under unauthorized network access (CWE‑300) and in‑band network injection (CWE‑506).

Affected Systems

Affected models include Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826‑T2 firmware 19.1101, Zbtlink ZBT‑7628 firmware 1.0.0.2.007, and Zbtlink ZBT‑ZBT7621 firmware 1.0.0.3.001. MoreQuick devices MQAC‑7620, MQAC‑7620A, MQAP‑7620, MQAP‑7620A, and MQAP‑7628 all ship with firmware 1.0.0.2.000. The list also includes AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP‑N10 firmware 1.0.0.2.044, all of which contain the vulnerable backdoor.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and the vulnerability is exploitable by any entity on the same network that can observe or send packets to the UDP channel. No EPSS value is provided, suggesting that recent exploitation data is unavailable, but the lack of a KEV listing does not mitigate the risk of this high‑impact flaw. An attacker with simple network access can hijack the cleartext channel, execute root‑level commands, and perform further compromise activities without authentication or privilege escalation within the device.

Generated by OpenCVE AI on August 27, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the impacted firmware with a version that has had the backdoor removed; obtain firmware from the vendor's official sources.
  • Inhibit outbound UDP traffic to the hard‑coded command‑and‑control server using firewall or network segmentation.
  • Disable or block the unauthenticated UDP service on the device to prevent the channel from being used.

Generated by OpenCVE AI on August 27, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
Title Zbtlink MQWrt yunmgrd Cloud C2 Implant
Weaknesses CWE-300
CWE-506
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-27T14:49:10.575Z

Reserved: 2026-08-14T18:01:19.917Z

Link: CVE-2026-74232

cve-icon Vulnrichment

Updated: 2026-08-27T14:49:06.539Z

cve-icon NVD

Status : Received

Published: 2026-08-27T13:18:33.917

Modified: 2026-08-27T17:19:51.953

Link: CVE-2026-74232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T14:45:17Z

Weaknesses
  • CWE-300

    Channel Accessible by Non-Endpoint

  • CWE-506

    Embedded Malicious Code