CVE-2026-34472
7.1
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN PSK, and PPPoE credentials. In some observed cases, configuration changes may also be performed without authentication.
Affected (2)
Products: Zte: Zxhn H188a Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.10p2_te |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.10p3n3_te |
| Running on/with | Platform Versions |
|---|---|
Zte Zxhn H188a | All versions |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (3)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.