CVE-2018-7358 is an improper change control vulnerability affecting specific firmware versions of the ZTE ZXHN H168N router, potentially allowing unauthorized users to perform unauthorized operations. With a CVSS score of 8.8 (HIGH), it is a network-adjacent attack requiring no user interaction, leading to high impacts on confidentiality, integrity, and availability. While not actively exploited in the wild and not on CISA's KEV catalog, a public exploit (EDB-45972) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0_pk1.2t2CPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h168n_firmware:2.2.0_pk1.2t2:*:*:*:*:*:*:* | ||
2.2.0_pk1.2t5CPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h168n_firmware:2.2.0_pk1.2t5:*:*:*:*:*:*:* | ||
2.2.0_pk11tCPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h168n_firmware:2.2.0_pk11t:*:*:*:*:*:*:* | ||
2.2.0_pk11t7CPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h168n_firmware:2.2.0_pk11t7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.