CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Zbtlink security advisory (AV26-779)

unknown
Serial number: AV26-779 Date: August 5, 2026 As of August 5, 2026, Zbtlink is affected by a vulnerability in the following products: CPE2801 Firmware 22.10.09 WE1026-5G-WD Firmware 21.04.07 WE1326 Firmware 22.02.18_1 WE2007 Firmware 23.08.12 WE2008-DSIM Firmware 23.08.11 WE2416 Firmware 21.03.22_1 WE3326 Firmware 20.09.30 WE5927 Firmware 22.08.10 WE5931 Firmware 22.05.31 WE5931AC Firmware 22.05.31 WE826-T3-DSIM Firmware 21.12.21 WG108 Firmware 21.08.06_1 WG1602 Firmware 23.10.11 WG1608-DSIM Firmware 23.03.16 WG209 Firmware 21.07.28 WG2105 Firmware 22.05.30 WG2107 Firmware 22.09.08 WG259 Firmware 21.03.23 WG3526 Firmware 22.11.01 ZBT-Z8102AX-2SIM Firmware 7.6.7.2-25.0814_114432 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitHub - ycsunjane/rctl: remote linux control | GitHub ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant | Advisories | VulnCheck Zbtlink - Firmware Download

CSIRTS triage

What
Unspecified vulnerability affects multiple Zbtlink networking and wireless products across various firmware versions.
Who is affected
Users of Zbtlink CPE, wireless, and networking devices with listed firmware versions.
Urgency
Moderate urgency; details are insufficient but advisory recommends reviewing and applying updates when available.
Action
Monitor Zbtlink for security updates and apply firmware patches as they become available for affected devices.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-05
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/zbtlink-security-advisory-av26-779

More from Canadian Centre for Cyber Security