Unauthenticated UDP command injection in Zbtlink router infosrvd service yields root (CVE-2026-74233)
VulnCheck's canary sensors observed exploitation attempts against this service today and added the CVE to their known-exploited catalog, so any Zbtlink router with UDP/9992 reachable can be taken over as root by a single crafted packet.
The infosrvd service listening on UDP/9992 across many Zbtlink router models accepts crafted packets that inject shell commands executed as root, and its authentication is defeated by a hardcoded salt and an all-zero wildcard MAC bypass. One unauthenticated packet is enough to fully compromise the device.
Affected: Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, WG3526, CTN720-W1, LF-1541, MT7620N firmware 19.1101; Zbtlink WE2426-C firmware 19.1112; Zbtlink WE5926-EC_QP firmware 20.0516; Zbtlink WF3526-P firmware 19.051; Zbtlink WRC1 firmware 20.0622
How to Test
Check whether your device is one of the listed models on the affected firmware versions, and probe whether UDP port 9992 (the infosrvd service) is reachable from untrusted networks, especially the WAN interface.
How to Mitigate
No vendor fix is cited in the current advisories: block or firewall UDP/9992 so the infosrvd service is unreachable from the internet and untrusted network segments, disable the service if your firmware allows it, monitor for crafted UDP traffic to port 9992, and watch Zbtlink for a firmware update addressing the flaw.