https://reddit.com/r/netsec/comments/1tjojra/cve202634474_preauth_credential_disclosure_in_zte/: CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
Published May 21, 2026
·Updated
Affected Software
2 affected components
ZTE ZXHN H298A=1.1
ZTE ZXHN H108N=2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-34474?
CVE-2026-34474 is classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive credentials.
2
How do I fix CVE-2026-34474?
To fix CVE-2026-34474, ensure that you apply the latest firmware update provided by ZTE for the ZXHN H298A and H108N routers.
3
What type of data is exposed in CVE-2026-34474?
CVE-2026-34474 exposes sensitive data, including the admin password, WLAN PSK, and ESSID, before user authentication.
4
Which ZTE routers are affected by CVE-2026-34474?
CVE-2026-34474 affects the ZTE ZXHN H298A and H108N router models.
5
Is CVE-2026-34474 a remote vulnerability?
Yes, CVE-2026-34474 can be exploited remotely since it allows credential disclosure without authentication.