CVE-2026-34472 identifies an unauthenticated credential disclosure vulnerability within the wizard interface of ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE routers. Rated 7.1 HIGH (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N), this flaw allows unauthenticated attackers on the local network to retrieve sensitive information, including the default administrator password, WLAN PSK, and PPPoE credentials, with some observed cases also permitting unauthorized configuration changes. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.10p2_teCPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h188a_firmware:6.0.10p2_te:*:*:*:*:*:*:* | ||
6.0.10p3n3_teCPE matchmatch criteria | cpe:2.3:o:zte:zxhn_h188a_firmware:6.0.10p3n3_te:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.