CRITICALCVSS 9.8Vulnerability

CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

Properties

severity
CRITICAL
cvss_severity
CRITICAL
cvss_score
9.8
retrieved_at
2026-09-25T15:10:03+00:00
score
9.8
last_source
NVD
cve_id
CVE-2026-74232
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-25T15:10:03+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-27T13:18:33.917
last_modified
2026-09-24T20:43:32.537

Related Entities (3)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (2)

→[Weakness]
→[Weakness]Embedded Malicious Code

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74232 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal