ZeroHour

CVE-2026-34474

mass

Unauthenticated Credential Leak in ZTE ZXHN H298A and H108N Routers

CVSS 3.1
7.5 high
EPSS
25%p98
Published
()
Modified
AI analysis

ZTE ZXHN H298A (version 1.1) and H108N (version 2.6) routers contain an information-disclosure flaw (CWE-200) in the web management interface. A crafted request to the interface causes the device to return sensitive device and account information, and in affected builds the response can include the administrator password and the WLAN pre-shared key, while some firmware versions expose only partial identifiers such as the serial number, ESSID, or MAC addresses. An attacker who retrieves the credentials can authenticate to the management interface as administrator and use the Wi-Fi key to join the wireless network, achieving authentication bypass and network compromise with no prior privileges or user interaction (CVSS 3.1: 7.5, network vector). The affected products are consumer routers typically supplied by internet service providers, so subscribers and ISP fleets running those specific builds are exposed. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 24.7% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.

What to do: Determine whether your router is an ZXHN H298A on firmware 1.1 or an H108N on firmware 2.6 and request updated firmware from ZTE or your ISP, as no fixed version is listed in the available data. Until patched, restrict the web interface to the LAN (disable WAN-side/remote management) and assume the administrator password and Wi-Fi passphrase are retrievable by any unauthenticated party that can reach the interface, then rotate both credentials after updating. ISPs operating fleets of these models should prioritize firmware audits given the elevated EPSS score.

Affected
ZTE ZXHN H298A1.1
ZTE ZXHN H108N2.6
Estimated exposure
masslikely millions of deployed ISP-supplied units, with hundreds of thousands potentially internet-exposed — Both models were mass-bundled consumer CPE issued across multiple ISP fleets, and historical internet-wide scans have shown hundreds of thousands of ZTE ZXHN devices exposing their web interfaces, implying an affected deployed base above…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authentication bypass and network compromise. Some firmware versions may expose only partial identifiers (e.g., serial number, ESSID, MAC addresses).

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.