CVE-2026-74232 is an embedded command-and-control backdoor, known as SPEAKINGSTONE, implemented by the yunmgrd service in specified Zbtlink and MoreQuick router and access-point firmware releases. yunmgrd initiates cleartext, unauthenticated UDP communications to hardcoded command-and-control infrastructure. An attacker able to intercept or hijack this network channel can issue commands that the implant executes with root privileges. The issue is also classified as CWE-300 because the command channel is accessible to a non-endpoint on the communication path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical firmware-level cloud C2/surveillance implant in ZBT-derived router firmware. The yunmgrd service beacons to an external C2 over UDP/10000, allowing remote root-level command execution and network/device surveillance capabilities, including credential theft and DNS hijacking.
A pre-installed yunmgrd command-and-control backdoor in specified Zbtlink, MoreQuick, and related router/access-point firmware. An unauthenticated network-path attacker can hijack its cleartext UDP C2 channel to execute commands as root, alter DNS, steal PPPoE credentials, and establish reverse SSH tunnels.
A critical firmware-embedded backdoor implant in affected Zbtlink and MoreQuick network devices. The unauthenticated cleartext UDP C2 channel can be hijacked by an on-path attacker, enabling root command execution, DNS modification, PPPoE credential exfiltration, and reverse SSH tunnels.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.