Skip to main content
CRITICAL

CVE-2026-74233

CVSS v3

9.8

CRITICAL

EPSS Score

2.6 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authenticat

Technical details

CVSS v3 Vector
3.1
Published
2026-08-27
Last Modified
2026-08-27

Frequently asked questions

What is CVE-2026-74233?

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authenticat

Is CVE-2026-74233 actively exploited?

Active exploitation of CVE-2026-74233 has not been confirmed. The EPSS score is 2.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-74233?

CVE-2026-74233 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-74233 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key