CVE-2026-34474

HIGH

ZTE ZXHN H298A 1.1/H108N 2.6 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-34474. PoCs published by Mina Nageh Salalma, minanagehsalalma.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in ZTE H298A and H108N routers. It sends HTTP GET requests to specific endpoints to retrieve plaintext administrator credentials, Wi-Fi PSK, ESSID, and serial number without requiring authentication.

Description

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authentication bypass and network compromise. Some firmware versions may expose only partial identifiers (e.g., serial number, ESSID, MAC addresses).

Exploits (2)

exploitdb WORKING POC
by Mina Nageh Salalma · textlocalmultiple
https://www.exploit-db.com/exploits/52592

This exploit demonstrates an unauthenticated information disclosure vulnerability in ZTE H298A and H108N routers. It sends HTTP GET requests to specific endpoints to retrieve plaintext administrator credentials, Wi-Fi PSK, ESSID, and serial number without requiring authentication.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ZTE ZXHN H298A 1.1, ZTE ZXHN H108N 2.6
No auth needed
Prerequisites: network access to the target router
devstral-2 · analyzed May 30, 2026 Full analysis →
github WORKING POC
by minanagehsalalma · csspoc
https://github.com/minanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

This repository contains functional exploit code for CVE-2026-34474, which exposes sensitive data (admin password, ESSID, Wi-Fi password, and serial number) from ZTE H298A and H108N devices via unauthenticated HTTP requests. The PoC scripts demonstrate the vulnerability by querying specific endpoints and extracting the exposed fields.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ZTE H298A and H108N devices
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed May 20, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0162
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Published May 06, 2026
Tracked Since May 07, 2026