{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mqap-7620a-1.0.0.2.000/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-74232"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["L3_V2_8 (3.0.0.4.528)","WE826-T2 (19.1101)","ZBT-7628 (1.0.0.2.007)","ZBT-ZBT7621 (1.0.0.3.001)","MQAC-7620 (1.0.0.2.000)","MQAC-7620A (1.0.0.2.000)","MQAP-7620 (1.0.0.2.000)","MQAP-7620A (1.0.0.2.000)","MQAP-7628 (1.0.0.2.000)","AP522 (1.0.0.2.014)","AP7628 (3.0.0.4.380)","HC5661A (3.0.0.4.380)","APG721B (19.0809)","HK300 (1.0.0.2.032)","MAP-N10 (1.0.0.2.044)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Zbtlink","MoreQuick"],"content_html":"\u003cp\u003eSecurity researchers have identified a critical vulnerability, CVE-2026-74232, affecting a wide range of Zbtlink and MoreQuick router models. The affected devices ship with a persistent backdoor service known as 'yunmgrd'. This service listens on an unauthenticated, cleartext UDP channel and communicates with a hardcoded command-and-control (C2) server.\u003c/p\u003e\n\u003cp\u003eAn attacker positioned on the network path can intercept or hijack these UDP communications to issue unauthorized commands, gaining remote code execution (RCE) with root privileges on the device. Once root access is achieved, attackers can perform full device control, including exfiltration of sensitive PPPoE credentials, hijacking of DNS entries for redirection purposes, and the establishment of persistent reverse SSH tunnels. Given the lack of authentication and the use of cleartext protocols, this vulnerability represents a significant risk for the confidentiality and integrity of network traffic passing through these devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows full administrative control over the affected routers. Successful exploitation enables attackers to gain persistence, steal sensitive network authentication credentials, perform man-in-the-middle attacks via DNS manipulation, and pivot deeper into the local network through reverse SSH tunnels. This affects multiple residential and small-business router models from Zbtlink and MoreQuick, impacting users across diverse sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all router hardware to identify the specific models and firmware versions listed in the affected products section.\u003c/li\u003e\n\u003cli\u003eIsolate any identified vulnerable hardware from internet-facing segments until the vendor provides patched firmware.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the network perimeter to block unauthorized UDP traffic to unknown destinations if specific C2 infrastructure IPs are identified in future intelligence.\u003c/li\u003e\n\u003cli\u003eMonitor network logs for unusual UDP traffic patterns originating from or destined to router management interfaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T13:40:12Z","date_published":"2026-08-27T13:40:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zbtlink-backdoor/","summary":"Multiple Zbtlink and MoreQuick router models contain an unauthenticated backdoor service, 'yunmgrd', which allows remote attackers to execute root commands and manipulate network traffic.","title":"Unauthenticated Backdoor in Zbtlink and MoreQuick Router Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-zbtlink-backdoor/"}],"language":"en","title":"CraftedSignal Threat Feed - MQAP-7620A (1.0.0.2.000)","version":"https://jsonfeed.org/version/1.1"}