top of page
perceptive_background_267k.jpg

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_…

Published:

27 August 2026 at 00:00:00

Alert date:

27 August 2026 at 16:01:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

Multiple Zbtlink router firmware versions contain a critical unauthenticated command injection vulnerability in the infosrvd service listening on UDP port 9992. A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root on affected devices. The vulnerability is exacerbated by a broken authentication mechanism that uses a hardcoded salt and an all-zero wildcard MAC address bypass, making the authentication completely ineffective. Affected devices include Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, WE2426-C, WE5926-EC_QP, WF3526-P, CTN720-W1, LF-1541, MT7620N, and WRC1 across various firmware versions. The vulnerability is tracked as CVE-2026-74233 and has been documented by VulnCheck, who published a detailed advisory and blog post. Given the root-level code execution capability and lack of authentication required, this vulnerability poses a critical risk to any exposed device.

Technical details

Mitigation steps:

Affected products:

Zbtlink WE1326 firmware 19.1101
Zbtlink WE357 firmware 19.1101
Zbtlink WE5926 firmware 19.1101
Zbtlink WE5926-WD firmware 19.1101
Zbtlink WE826-Q firmware 19.1101
Zbtlink WE826-T2 firmware 19.1101
Zbtlink WE826-WD firmware 19.1101
Zbtlink WG108 firmware 19.1101
Zbtlink WG3526 firmware 19.1101
Zbtlink WE2426-C firmware 19.1112
Zbtlink WE5926-EC_QP firmware 20.0516
Zbtlink WF3526-P firmware 19.051
CTN720-W1 firmware 19.1101
LF-1541 firmware 19.1101
MT7620N firmware 19.1101
WRC1 firmware 20.0622

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page