Vulnerability threat dossier

CVE-2026-74233

ZbtlinkWE1326

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

VTP deterministic threat36.5of 100 · CVSS excluded

VTP analyst assessment

ZBT router infosrvd command injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factCONFIRMED

Assessment

Critical unauthenticated command injection in the UDP/9992 infosrvd service across multiple ZBT and related router firmware builds. Independent ENISA EU KEV evidence lists it as known exploited, while a press assertion also reports exploitation with unknown independence.

Why it matters

  • A remote unauthenticated attacker may obtain root-level command execution on affected network-edge devices.
  • CVSS 9.3 indicates high confidentiality, integrity, and availability impact; EPSS 0.02633 does not negate the exploitation evidence.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The press report's independence is unknown, and the supplied data does not describe exploitation scale or tooling reliability.

Affected-product CPEs, local exposure, and first-party observations are unavailable.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Affected models and firmware with UDP/9992 reachable from untrusted networks.

AI baseline history (4)
  1. BASELINE ASSESSED
    ZBT router infosrvd command injectiongpt-5.6-sol · high
  2. BASELINE ASSESSED
    ZBT-family router infosrvd command injectiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    ZBT-family router infosrvd command injectiongpt-5.6-sol · high
  4. BASELINE ASSESSED
    ZBT router implant with reported exploitationgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.3 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0385th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.03; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:e808cf0542fbd8cb8233fef680a0ad1dea0f83546cd8a9f102183eb4452e619fACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-74233ACTIVE
Evidence
04

Event history

Threat timeline

  1. 10:5828 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0027 Aug
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

CVE-2025-15628CVE-2025-30237CVE-2025-30241CVE-2026-0251CVE-2026-15307CVE-2026-15337CVE-2026-15830CVE-2026-15920CVE-2026-16348CVE-2026-17106CVE-2026-18431CVE-2026-18885CVE-2026-18886CVE-2026-19516CVE-2026-19598CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-59565CVE-2026-59567CVE-2026-59568CVE-2026-65643CVE-2026-66747CVE-2026-67618CVE-2026-69251CVE-2026-69253CVE-2026-69254CVE-2026-69255CVE-2026-69256CVE-2026-69259CVE-2026-69264CVE-2026-70426CVE-2026-70470CVE-2026-70477CVE-2026-73484CVE-2026-73485CVE-2026-73486CVE-2026-73487CVE-2026-73554CVE-2026-73601CVE-2026-73602CVE-2026-74232CVE-2026-74233CVE-2026-74820CVE-2026-75149CVE-2026-75604CVE-2026-76639CVE-2026-76640CVE-2026-77537CVE-2026-77550CVE-2026-77554CVE-2026-77775CVE-2026-77776CVE-2026-7791CVE-2026-78541CVE-2026-78935CVE-2026-79012CVE-2026-79052CVE-2026-79054CVE-2026-79121CVE-2026-79150CVE-2026-79200CVE-2026-79224CVE-2026-79282CVE-2026-79290CVE-2026-81578CVE-2026-82078CVE-2026-9254
Separate evidence group
Original

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

CVE-2026-66747CVE-2026-74232CVE-2026-74233
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-74233

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-74233
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.5vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.53 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-321, CWE-78
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.