Multiple CVEs Disclose Pre-auth Credential Exposure in ZTE Routers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-34472 and CVE-2026-34474 reveal critical pre-authentication credential exposure vulnerabilities in ZTE routers. CVE-2026-34472 affects the ZTE H188A V6 router, allowing unauthenticated access to sensitive configuration values. CVE-2026-34474 impacts the ZTE ZXHN H298A and H108N routers, where an ETHCheat branch exposes credential-bearing HTML before authentication. Both vulnerabilities were published in March and May 2026, with the first public proof of concept (PoC) released on May 19, 2026. The flaws enable attackers to retrieve admin credentials and WLAN settings, posing significant risks to network security. Users of affected ZTE router models are advised to take immediate action to mitigate the risks. The PoC for both vulnerabilities was submitted by the same user, indicating a coordinated disclosure effort.
Key Points: • CVE-2026-34472 affects ZTE H188A V6 routers, exposing sensitive credentials pre-authentication. • CVE-2026-34474 impacts ZTE ZXHN H298A and H108N routers, allowing credential disclosure via ETHCheat. • Both vulnerabilities have public PoCs released, increasing the risk of exploitation.