CVE-2026-34473: High severity ZTE ZTE H8102E vulnerability

Published May 6, 2026
·
Updated

Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering, the management interface may become unresponsive until the device is rebooted. This may affect any firmware version prior to 2022 (reporter observation). The supplier stated that devices are not vulnerable since 2021-03-23; operator firmware may vary.

Affected Software

17 affected components
ZTE ZTE H8102E<2022, <2021-03-23
ZTE ZTE H168N<2022, <2021-03-23
ZTE ZTE H167A<2022, <2021-03-23
ZTE ZTE H199A<2022, <2021-03-23
ZTE ZTE H288A<2022, <2021-03-23
ZTE ZTE H198A<2022, <2021-03-23
ZTE ZTE H267A<2022, <2021-03-23
ZTE ZTE H267N<2022, <2021-03-23
ZTE ZTE H268A<2022, <2021-03-23
ZTE ZTE H388X<2022, <2021-03-23
ZTE ZTE H196A<2022, <2021-03-23
ZTE ZTE H369A<2022, <2021-03-23
ZTE ZTE H268N<2022, <2021-03-23
ZTE ZTE H208N<2022, <2021-03-23
ZTE ZTE H367N<2022, <2021-03-23
ZTE ZTE H181A<2022, <2021-03-23
ZTE ZTE H196Q<2022, <2021-03-23

Event History

May 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
May 29, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
11:05 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34473?

CVE-2026-34473 is classified as a denial-of-service vulnerability, which allows unauthenticated attackers to disrupt the router's web interface.

2

How do I fix CVE-2026-34473?

To fix CVE-2026-34473, update the firmware of the affected ZTE models to the latest version provided by the vendor.

3

Which devices are affected by CVE-2026-34473?

CVE-2026-34473 affects several models including ZTE H8102E, H168N, H167A, and various others listed in the vulnerability details.

4

Can CVE-2026-34473 be exploited remotely?

Yes, CVE-2026-34473 can be exploited remotely since it does not require authentication to trigger the denial-of-service condition.

5

What is the impact of CVE-2026-34473 on my network?

The impact of CVE-2026-34473 can lead to service interruptions and unavailability of the affected routers' web interfaces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203