PT-2026-82486 · Morequick+7 · Mqap-7628+14
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zbtlink L3 V2 8 version 3.0.0.4.528
Zbtlink WE826-T2 version 19.1101
Zbtlink ZBT-7628 version 1.0.0.2.007
Zbtlink ZBT-ZBT7621 version 1.0.0.3.001
MoreQuick MQAC-7620 version 1.0.0.2.000
MoreQuick MQAC-7620A version 1.0.0.2.000
MoreQuick MQAP-7620 version 1.0.0.2.000
MoreQuick MQAP-7620A version 1.0.0.2.000
MoreQuick MQAP-7628 version 1.0.0.2.000
AP522 version 1.0.0.2.014
AP7628 version 3.0.0.4.380
HC5661A version 3.0.0.4.380
APG721B version 19.0809
HK300 version 1.0.0.2.032
MAP-N10 version 1.0.0.2.044
Description
These devices ship with a backdoor command-and-control implant called
yunmgrd. This implant communicates via an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker positioned on the network path can hijack this channel to execute arbitrary commands with root privileges. Additionally, the attacker can modify DNS entries, exfiltrate PPPoE credentials, and establish reverse SSH tunnels.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ap522
Ap7628
Apg721B
Hc5661A
Hk300
L3 V2 8
Map-N10
Mqac-7620
Mqac-7620A
Mqap-7620
Mqap-7620A
Mqap-7628
We826-T2
Zbt-7628
Zbt-Zbt7621