PT-2026-29045 · Zte · Zxhn H188A

Minanagehsalalma

·

Published

2026-03-30

·

Updated

2026-05-20

·

CVE-2026-34472

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZTE ZXHN H188A versions V6.0.10P2 TE through V6.0.10P3N3 TE
Description An issue exists that allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface. These credentials include the default administrator password, WLAN PSK, and PPPoE credentials. In some instances, configuration changes can also be made without authentication through the wizard interface.
Recommendations Versions V6.0.10P2 TE and V6.0.10P3N3 TE are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-34472

Affected Products

Zxhn H188A