Vulnerability threat dossier

CVE-2026-74232

ZbtlinkL3_V2_8

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

VTP deterministic threat36.1of 100 · CVSS excluded

VTP analyst assessment

Critical router firmware implants with public exploitation reporting

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factCONFIRMED

Assessment

CVE-2026-74232 affects numerous Zbtlink and related router firmware products. Available reporting describes factory implants enabling unauthenticated root access, while ENISA EU KEV membership indicates known public exploitation. This establishes global exploitation context, not VTP observation.

Why it matters

  • Unauthenticated remote root access can enable complete compromise of affected network devices.
  • The affected list spans multiple router models and firmware families.
  • ENISA EU KEV listing supports that exploitation is known publicly.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied bundle contains no VTP sensor telemetry or evidence of affected-device presence.

The press reporting's independence is unknown and the available excerpt does not provide exploitation campaign details.

No affected CPEs or remediation details are supplied.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Identify deployed Zbtlink, MoreQuick, and named related router models and compare firmware versions with the affected list.

AI baseline history (2)
  1. BASELINE ASSESSED
    Critical router firmware implants with public exploitation reportinggpt-5.6-terra · low
  2. BASELINE ASSESSED
    Reported zero-day ZBT router implantgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.3 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0040th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:e808cf0542fbd8cb8233fef680a0ad1dea0f83546cd8a9f102183eb4452e619fACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-74232ACTIVE
Evidence
04

Event history

Threat timeline

  1. 10:5828 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0027 Aug
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

CVE-2025-15628CVE-2025-30237CVE-2025-30241CVE-2026-0251CVE-2026-15307CVE-2026-15337CVE-2026-15830CVE-2026-15920CVE-2026-16348CVE-2026-17106CVE-2026-18431CVE-2026-18885CVE-2026-18886CVE-2026-19516CVE-2026-19598CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-59565CVE-2026-59567CVE-2026-59568CVE-2026-65643CVE-2026-66747CVE-2026-67618CVE-2026-69251CVE-2026-69253CVE-2026-69254CVE-2026-69255CVE-2026-69256CVE-2026-69259CVE-2026-69264CVE-2026-70426CVE-2026-70470CVE-2026-70477CVE-2026-73484CVE-2026-73485CVE-2026-73486CVE-2026-73487CVE-2026-73554CVE-2026-73601CVE-2026-73602CVE-2026-74232CVE-2026-74233CVE-2026-74820CVE-2026-75149CVE-2026-75604CVE-2026-76639CVE-2026-76640CVE-2026-77537CVE-2026-77550CVE-2026-77554CVE-2026-77775CVE-2026-77776CVE-2026-7791CVE-2026-78541CVE-2026-78935CVE-2026-79012CVE-2026-79052CVE-2026-79054CVE-2026-79121CVE-2026-79150CVE-2026-79200CVE-2026-79224CVE-2026-79282CVE-2026-79290CVE-2026-81578CVE-2026-82078CVE-2026-9254
Separate evidence group
Original

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

CVE-2026-66747CVE-2026-74232CVE-2026-74233
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-74232

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-74232
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.1vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.09 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-300, CWE-506
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.