CVE-2026-34473: High severity ZTE ZTE H8102E vulnerability
Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering, the management interface may become unresponsive until the device is rebooted. This may affect any firmware version prior to 2022 (reporter observation). The supplier stated that devices are not vulnerable since 2021-03-23; operator firmware may vary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34473?
CVE-2026-34473 is classified as a denial-of-service vulnerability, which allows unauthenticated attackers to disrupt the router's web interface.
How do I fix CVE-2026-34473?
To fix CVE-2026-34473, update the firmware of the affected ZTE models to the latest version provided by the vendor.
Which devices are affected by CVE-2026-34473?
CVE-2026-34473 affects several models including ZTE H8102E, H168N, H167A, and various others listed in the vulnerability details.
Can CVE-2026-34473 be exploited remotely?
Yes, CVE-2026-34473 can be exploited remotely since it does not require authentication to trigger the denial-of-service condition.
What is the impact of CVE-2026-34473 on my network?
The impact of CVE-2026-34473 can lead to service interruptions and unavailability of the affected routers' web interfaces.