<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MoreQuick - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/morequick/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 13:40:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/morequick/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Backdoor in Zbtlink and MoreQuick Router Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-08-zbtlink-backdoor/</link><pubDate>Thu, 27 Aug 2026 13:40:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-zbtlink-backdoor/</guid><description>Multiple Zbtlink and MoreQuick router models contain an unauthenticated backdoor service, 'yunmgrd', which allows remote attackers to execute root commands and manipulate network traffic.</description><content:encoded><![CDATA[<p>Security researchers have identified a critical vulnerability, CVE-2026-74232, affecting a wide range of Zbtlink and MoreQuick router models. The affected devices ship with a persistent backdoor service known as 'yunmgrd'. This service listens on an unauthenticated, cleartext UDP channel and communicates with a hardcoded command-and-control (C2) server.</p>
<p>An attacker positioned on the network path can intercept or hijack these UDP communications to issue unauthorized commands, gaining remote code execution (RCE) with root privileges on the device. Once root access is achieved, attackers can perform full device control, including exfiltration of sensitive PPPoE credentials, hijacking of DNS entries for redirection purposes, and the establishment of persistent reverse SSH tunnels. Given the lack of authentication and the use of cleartext protocols, this vulnerability represents a significant risk for the confidentiality and integrity of network traffic passing through these devices.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows full administrative control over the affected routers. Successful exploitation enables attackers to gain persistence, steal sensitive network authentication credentials, perform man-in-the-middle attacks via DNS manipulation, and pivot deeper into the local network through reverse SSH tunnels. This affects multiple residential and small-business router models from Zbtlink and MoreQuick, impacting users across diverse sectors.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform an inventory of all router hardware to identify the specific models and firmware versions listed in the affected products section.</li>
<li>Isolate any identified vulnerable hardware from internet-facing segments until the vendor provides patched firmware.</li>
<li>Implement egress filtering at the network perimeter to block unauthorized UDP traffic to unknown destinations if specific C2 infrastructure IPs are identified in future intelligence.</li>
<li>Monitor network logs for unusual UDP traffic patterns originating from or destined to router management interfaces.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>