Command Injection Vulnerability in Zbtlink Firmware Products
CVE-2026-74233
Key Information:
Badges
What is CVE-2026-74233?
A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands as root. As a result, devices running affected firmware versions are at significant risk of unauthorized access and potential system compromise.
Affected Version(s)
CTN720-W1 19.1101
LF-1541 19.1101
MT7620N 19.1101
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
