Zbtlink MQWrt infosrvd Command Injection
70Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.3epss 2.6%
from disclosure to weapon
Published on NVDAug 27
VulnCheckAug 27
exploitation probability
2.6%top 15% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Unknown · CTN720-W1Unknown · LF-1541Unknown · MT7620NUnknown · WRC1Zbtlink · WE1326Zbtlink · WE2426-CZbtlink · WE357Zbtlink · WE5926Zbtlink · WE5926-EC_QPZbtlink · WE5926-WDZbtlink · WE826-QZbtlink · WE826-T2Zbtlink · WE826-WDZbtlink · WF3526-PZbtlink · WG108Zbtlink · WG3526public PoCs found — 1
cve_referencevulncheck.com/blog/zbt-darklantern-speakingstoneunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.