Beschreibung
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router-s web management interface, including the default administrator password, WLAN PSK, and PPPoE credentials. In some observed cases, configuration changes may also be performed without authentication.
CVSS 7.1EPSS 8.943%Risiko 1.28
Quelle öffnen- Veröffentlicht
- 2026-03-30 16:16:07
- Betroffene Versionen
- cannotmatch
- Typ
- Firmware
- Vektor
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N