CVE-2026-74233 is an unauthenticated OS command-injection vulnerability in the infosrvd service of multiple Zbtlink and related router firmware builds. The service processes crafted UDP requests in a manner that permits attacker-controlled operating-system command execution. Its authentication controls are ineffective: authentication relies on a hardcoded salt, and an all-zero wildcard MAC-address value bypasses validation. Affected versions include specified firmware builds for Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, WE2426-C, WE5926-EC_QP, and WF3526-P devices, as well as CTN720-W1, LF-1541, MT7620N, and WRC1 devices.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated command-injection backdoor in the infosrvd WAN listener of affected ZBT router firmware. Internet-reachable UDP port 9992 accepts crafted packets that result in root shell command execution; its token and MAC-address checks can be bypassed by design.
An unauthenticated remote command-injection vulnerability in the infosrvd UDP service on port 9992 in affected Zbtlink and related router firmware. Attackers can execute arbitrary commands as root because the service authentication can be bypassed through an all-zero wildcard MAC and uses a hardcoded salt.
Critical unauthenticated remote OS command injection in the UDP/9992 infosrvd service on specified Zbtlink/MQWRT-derived router firmware. Crafted UDP packets enable arbitrary command execution as root, aided by ineffective authentication based on a hardcoded salt and an all-zero wildcard-MAC bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.