CVE-2026-74233
Zbtlink MQWrt infosrvd Command Injection
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
| CWE | CWE-321 CWE-78 |
| Vendor | zbtlink |
| Product | we1326 |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for zbtlink we1326
Be the first to know when new critical vulnerabilities affecting zbtlink we1326 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Zbtlink / WE1326
19.1101
Zbtlink / WE2426-C
19.1112
Zbtlink / WE357
19.1101
Zbtlink / WE5926
19.1101
Zbtlink / WE5926-EC_QP
20.0516
Zbtlink / WE5926-WD
19.1101
Zbtlink / WE826-Q
19.1101
Zbtlink / WE826-T2
19.1101
Zbtlink / WE826-WD
19.1101
Zbtlink / WF3526-P
19.051
Zbtlink / WG108
19.1101
Zbtlink / WG3526
19.1101
Unknown / CTN720-W1
19.1101
Unknown / LF-1541
19.1101
Unknown / MT7620N
19.1101
Unknown / WRC1
20.0622
References
Credits
Jacob Baines of VulnCheck