Unauthenticated root code execution via outbound C2
Published Aug 5, 2026 · Updated Aug 5, 2026
Embedded malicious code in 20 Zbtlink router firmware builds allows remote attackers to execute commands as root through outbound C2 traffic. The boot-started librctl.so package disguises its root userland client as kworker and passes every unauthenticated C2 string to popen(). An attacker must answer the hardcoded address, control its DNS or network path, or acquire the fallback domain; success grants arbitrary root commands and an interactive shell.
Summary
What happened
Embedded malicious code in 20 Zbtlink router firmware builds allows remote attackers to execute commands as root through outbound C2 traffic. The boot-started librctl.so package disguises its root userland client as kworker and passes every unauthenticated C2 string to popen(). An attacker must answer the hardcoded address, control its DNS or network path, or acquire the fallback domain; success grants arbitrary root commands and an interactive shell.
The record
- CVE
- CVE-2026-66747
- Published
- Aug 5, 2026
- Updated
- Aug 5, 2026
- Vendor
- Shenzhen Zhibotong Electronics Co., Ltd.
- Product
- WE5931 Firmware
- Classifications
- CWE-506, CAPEC-442, CAPEC-636, CAPEC-448, T1059.004
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 5, 2026CVE publishedPublication date reported by the CVE source.
- Aug 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=22.05.31
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- ENDLESSDOORS go-exploit protocol hijackfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo