EIP-2026-101117

PRE-CVE

ZTE AC 3633R USB Modem - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101117. PoCs published by Vishnu.

AI-analyzed exploit summary This is a vulnerability writeup describing authentication bypass and DoS vulnerabilities in ZTE AC3633R USB modems. The authentication bypass can be achieved by sending a 121-character string in the username or password field, while a DoS can be triggered with a 130-character input.

Description

ZTE AC 3633R USB Modem - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP
by Vishnu · textdoshardware
https://www.exploit-db.com/exploits/37199

This is a vulnerability writeup describing authentication bypass and DoS vulnerabilities in ZTE AC3633R USB modems. The authentication bypass can be achieved by sending a 121-character string in the username or password field, while a DoS can be triggered with a 130-character input.

Classification
Writeup 90%
Attack Type
Auth Bypass | Dos
Complexity
Trivial
Reliability
Theoretical
Target: ZTE AC3633R (MTS Ultra Wifi Modem)
No auth needed
Prerequisites: Physical or local network access to the modem
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026