ThreatCluster

Multiple CVEs Disclose Pre-auth Credential Exposure in ZTE Routers

First seen 21 May 2026, 17:07 UTC Reddit 76% similarity 71

Article Content

Browse articles
ThreatCluster

CVE-2026-34472 and CVE-2026-34474 reveal critical pre-authentication credential exposure vulnerabilities in ZTE routers. CVE-2026-34472 affects the ZTE H188A V6 router, allowing unauthenticated access to sensitive configuration values. CVE-2026-34474 impacts the ZTE ZXHN H298A and H108N routers, where an ETHCheat branch exposes credential-bearing HTML before authentication. Both vulnerabilities were published in March and May 2026, with the first public proof of concept (PoC) released on May 19, 2026. The flaws enable attackers to retrieve admin credentials and WLAN settings, posing significant risks to network security. Users of affected ZTE router models are advised to take immediate action to mitigate the risks. The PoC for both vulnerabilities was submitted by the same user, indicating a coordinated disclosure effort.

Key Points: • CVE-2026-34472 affects ZTE H188A V6 routers, exposing sensitive credentials pre-authentication. • CVE-2026-34474 impacts ZTE ZXHN H298A and H108N routers, allowing credential disclosure via ETHCheat. • Both vulnerabilities have public PoCs released, increasing the risk of exploitation.

ThreatCluster AI

Timeline

2026-03-30
CVE-2026-34472 published
A pre-authentication credential exposure vulnerability in ZTE H188A V6 routers was disclosed.
Article 1
2026-05-06
CVE-2026-34474 published
A pre-authentication credential disclosure vulnerability in ZTE ZXHN H298A and H108N routers was disclosed.
Article 2
2026-05-19
First public PoCs released
Public proof of concepts for CVE-2026-34472 and CVE-2026-34474 were made available, demonstrating the vulnerabilities.
Article 1
Recent
Security advisory issued
Users of affected ZTE routers are urged to take immediate action to secure their devices against potential exploitation.
Article 2

Community

Browse all →

Tracked Entities in This Story