CVE-2026-34474
massUnauthenticated Credential Leak in ZTE ZXHN H298A and H108N Routers
ZTE ZXHN H298A (version 1.1) and H108N (version 2.6) routers contain an information-disclosure flaw (CWE-200) in the web management interface. A crafted request to the interface causes the device to return sensitive device and account information, and in affected builds the response can include the administrator password and the WLAN pre-shared key, while some firmware versions expose only partial identifiers such as the serial number, ESSID, or MAC addresses. An attacker who retrieves the credentials can authenticate to the management interface as administrator and use the Wi-Fi key to join the wireless network, achieving authentication bypass and network compromise with no prior privileges or user interaction (CVSS 3.1: 7.5, network vector). The affected products are consumer routers typically supplied by internet service providers, so subscribers and ISP fleets running those specific builds are exposed. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 24.7% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Determine whether your router is an ZXHN H298A on firmware 1.1 or an H108N on firmware 2.6 and request updated firmware from ZTE or your ISP, as no fixed version is listed in the available data. Until patched, restrict the web interface to the LAN (disable WAN-side/remote management) and assume the administrator password and Wi-Fi passphrase are retrievable by any unauthenticated party that can reach the interface, then rotate both credentials after updating. ISPs operating fleets of these models should prioritize firmware audits given the elevated EPSS score.
| ZTE ZXHN H298A | 1.1 |
| ZTE ZXHN H108N | 2.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authentication bypass and network compromise. Some firmware versions may expose only partial identifiers (e.g., serial number, ESSID, MAC addresses).
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.