Daily Wire · Free EditionConfirmed Threats. Zero Noise.

The Exploit Bulletin

What Security Teams Must Act On Today

From the edition of

Friday, August 28, 2026

Remote Code ExecutioncriticalCVSS 9.3CVE-2026-74232

Factory C2 implant (yunmgrd) in Zbtlink and MoreQuick router firmware enables unauthenticated remote root (CVE-2026-74232)

VulnCheck added this to its known-exploited catalog on 2026-08-27 after sinkholing the implant's hardcoded C2 domain and watching live devices beacon in, meaning any team still running these routers has an unauthenticated root backdoor an attacker on the network path can hijack.

Multiple Zbtlink and MoreQuick router firmware images ship with a command-and-control implant, yunmgrd, that listens on an unauthenticated cleartext UDP channel tied to a hardcoded C2 domain. Anyone controlling that domain or the network path can run commands as root on the device; VulnCheck took over the domain and found live implants beaconing home.

Affected: Zbtlink L3_V2_8 firmware 3.0.0.4.528; Zbtlink WE826-T2 firmware 19.1101; Zbtlink ZBT-7628 firmware 1.0.0.2.007; Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001; MoreQuick MQAC-7620/MQAC-7620A/MQAP-7620/MQAP-7620A/MQAP-7628 firmware 1.0.0.2.000; AP522 firmware 1.0.0.2.014; AP7628 and HC5661A firmware 3.0.0.4.380; APG721B firmware 19.0809; HK300 firmware 1.0.0.2.032; MAP-N10 firmware 1.0.0.2.044

How to Test

Check whether your device model and firmware version match the affected list; inspect the device for a running yunmgrd process and monitor egress traffic for cleartext UDP beacons from the router to unknown external hosts, which indicates the implant is active.

How to Mitigate

No vendor fix is published. Block all outbound UDP from these routers to untrusted destinations at an upstream firewall, and plan to reflash with trusted third-party firmware or replace the device — the implant ships in the factory image, so a configuration change alone does not remove it.