CVE-2026-74232, designated SPEAKINGSTONE, is an embedded command-and-control implant implemented by the yunmgrd service in specified Zbtlink, MoreQuick, and rebranded router and access-point firmware builds. yunmgrd initiates cleartext, unauthenticated UDP communications with hardcoded command-and-control infrastructure. An unauthenticated attacker able to intercept or inject traffic on this channel can hijack the implant protocol and cause arbitrary commands to execute with root privileges. The implant also includes capabilities for WAN PPPoE credential collection, DNS-hijack-list manipulation, LAN traffic redirection, and reverse SSH tunnel establishment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical pre-installed backdoor/spy implant in Shenzhen Zhibotong Electronics (ZBT) router firmware. It enables remote root command execution, PPPoE credential theft, DNS manipulation, LAN-device redirection, and reverse SSH tunneling, including from behind NAT because the router initiates C2 communications.
A factory-installed surveillance implant in ZBT-derived router firmware that provides remote root-level command execution and outbound C2 communications, including credential theft and reverse tunneling.
A critical firmware-level cloud C2/surveillance implant in ZBT-derived router firmware. The yunmgrd service beacons to an external C2 over UDP/10000, allowing remote root-level command execution and network/device surveillance capabilities, including credential theft and DNS hijacking.
A pre-installed yunmgrd command-and-control backdoor in specified Zbtlink, MoreQuick, and related router/access-point firmware. An unauthenticated network-path attacker can hijack its cleartext UDP C2 channel to execute commands as root, alter DNS, steal PPPoE credentials, and establish reverse SSH tunnels.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.