# CVE-2026-74233

## Summary

- **CVE ID:** CVE-2026-74233
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-321, CWE-78
- **Published:** Aug 27, 2026
- **Last Modified:** Aug 27, 2026

## Description

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

## Affected Products

- Zbtlink — WE1326 (19.1101)
- Zbtlink — WE2426-C (19.1112)
- Zbtlink — WE357 (19.1101)
- Zbtlink — WE5926 (19.1101)
- Zbtlink — WE5926-EC_QP (20.0516)
- Zbtlink — WE5926-WD (19.1101)
- Zbtlink — WE826-Q (19.1101)
- Zbtlink — WE826-T2 (19.1101)
- Zbtlink — WE826-WD (19.1101)
- Zbtlink — WF3526-P (19.051)
- Zbtlink — WG108 (19.1101)
- Zbtlink — WG3526 (19.1101)
- Unknown — CTN720-W1 (19.1101)
- Unknown — LF-1541 (19.1101)
- Unknown — MT7620N (19.1101)
- Unknown — WRC1 (20.0622)

## References

- [CNA](http://vulncheck.com/blog/zbt-darklantern-speakingstone)
- [CNA](https://www.vulncheck.com/advisories/zbtlink-mqwrt-infosrvd-command-injection)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.63%
- **EPSS Percentile:** 84.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._