Backdoor implant in Zbtlink and MoreQuick routers allows unauthenticated root access
AI analysis
A range of Zbtlink (ZBT) and MoreQuick routers ship from the factory with an embedded backdoor implant called yunmgrd that opens an unauthenticated, cleartext UDP command-and-control channel to a hardcoded remote server. Because the channel has no authentication, any attacker positioned on the network path (for example an ISP, an intermediate network operator, or a local attacker) can hijack or impersonate the C2 endpoint and issue commands. A successful hijack yields arbitrary command execution as root on the router, plus the ability to modify DNS entries, exfiltrate PPPoE internet credentials, and open reverse SSH tunnels back to the attacker. Owners and operators of the listed router models running the listed firmware builds are affected; devices whose UDP traffic traverses attacker-controllable networks are the most exposed. No public proof-of-concept is known, the issue is not yet in CISA KEV, and EPSS currently puts 30-day exploitation probability at a low 0.5%, with no confirmed exploitation reported.
What to do: Check inventory for the listed models, verify running firmware against the affected builds, and obtain patched firmware from Zbtlink/MoreQuick or the seller (no fixed versions are specified in available data). Until patched, block or monitor the implant's outbound UDP traffic to its hardcoded C2 server (e.g., via egress filtering), watch for unexpected outbound UDP flows and reverse SSH tunnels from these devices, and rotate PPPoE credentials if compromise is suspected.
Affected
| Zbtlink L3_V2_8 | firmware 3.0.0.4.528 |
| Zbtlink WE826-T2 | firmware 19.1101 |
| Zbtlink ZBT-7628 | firmware 1.0.0.2.007 |
| Zbtlink ZBT-ZBT7621 | firmware 1.0.0.3.001 |
| MoreQuick MQAC-7620 | firmware 1.0.0.2.000 |
| MoreQuick MQAC-7620A | firmware 1.0.0.2.000 |
| MoreQuick MQAP-7620 | firmware 1.0.0.2.000 |
| MoreQuick MQAP-7620A | firmware 1.0.0.2.000 |
| MoreQuick MQAP-7628 | firmware 1.0.0.2.000 |
| Zbtlink AP522 | firmware 1.0.0.2.014 |
| Zbtlink AP7628 | firmware 3.0.0.4.380 |
| Zbtlink HC5661A | firmware 3.0.0.4.380 |
Estimated exposure
moderatelikely on the order of tens of thousands of devices deployed worldwide, of which likely only thousands are directly internet-exposed — No public install counts or scan data are available, so this is a deployment-pattern estimate: these are low-cost Chinese SOHO/ISP routers sold through online marketplaces and bundled by small ISPs, and the affected devices are limited to…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.