Where
-Infinity
0

Disclosure/write-up for CVE-2021-21735 affecting the ZTE ZXHN H168N V3.5.

The issue is cataloged as information disclosure, but the useful part is the authorization failure: wizard handlers under the setup surface exposed PPPoE and WLAN material that should have required authenticated configuration access. Firmware analysis points to a brittle whitelist decision around the QuickSetup flow, including routes such as wizardpppoelua.lua and wizardwlanconfiglua.lua.

The write-up keeps secrets redacted and focuses on the route behavior, firmware logic, deployment-dependent admin compromise path, disclosure timeline, and the ZTE Low vs NVD Medium severity split.

First published (updated )
Social
reddit

I published a write-up on CVE-2021-21735 in the ZTE ZXHN H168N V3.5.

The bug was treated as an information disclosure, but the exposed data was not harmless telemetry. Wizard routes leaked PPPoE and WLAN material, and in some ISP deployments the PPPoE identifier could map into the hidden admin credential model. That changes the practical impact from “data leak” to possible router admin compromise and Wi-Fi compromise.

The write-up walks through the redacted evidence, firmware routing logic, affected/fixed versions, disclosure timeline, and why the ZTE 3.5 Low rating and NVD 6.5 Medium rating tell different stories.

First published (updated )
Social
reddit
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0EG1T4TE.

First published (updated )
Severity
8.8
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

ZTE ZXHN H168N product with versions V2.2.0PK1.2T5, V2.2.0PK1.2T2, V2.2.0PK11T7 and V2.2.0PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.

First published (updated )
Severity
8.8
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

ZTE ZXHN H168N product with versions V2.2.0PK1.2T5, V2.2.0PK1.2T2, V2.2.0PK11T7 and V2.2.0PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203