CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Called exploited the same day it was disclosed.
Measured from the CVE publication date to the earliest of 2 KEV catalogues that list it.
The life of this vulnerability
- CVE published
- First KEV listingsame day
- Last sighting1d
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federaldoes not list it
- EUVDENISA, European Unionlisted Aug 27, 2026
- VulnCheck KEVcommercial researchlisted Aug 27, 2026
- CIRCLaggregator, mirrors the abovedoes not list it
2 catalogues list it. CIRCL aggregates the others and is shown but not counted.
Public exploitation evidence
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-7
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-7
- reported exploitationwww.vulncheck.com/blog/zbt-darklantern-speakingstone
3 public reports collected from VulnCheck and CIRCL, first on Aug 27, 2026. Each links to its original source. We have not verified them.
Description
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.