CVE-2021-21735 is an information disclosure vulnerability affecting ZTE ZXHN H168N routers, including all versions up to V3.5.0_EG1T4_TE / V3.5 as described in the provided content. The firmware exposes quick-setup wizard endpoints that can be reached without authentication due to improper permission settings and endpoint allowlisting via a QuickSetupEnable branch. By invoking the wizard's GetPassword action, an unauthenticated attacker can retrieve sensitive configuration data, including PPPoE credentials such as ADUsername and VDUsername and the WLAN KeyPassphrase. The issue is therefore an unauthenticated credential disclosure flaw in the router's web management interface. The provided context further indicates that, in some ISP-deployed configurations, the disclosed Wi-Fi password may also be reused as the default administrator password, creating a direct path from information disclosure to administrative compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit/write-up package for CVE-2021-21735 affecting the ZTE ZXHN H168N V3.5. It contains 5 files total: a Python bulk PoC (zte_zxhn_h168n_bulk_poc.py), a GitHub Pages-style HTML article (index.html), a README, requirements.txt, and a .nojekyll marker. The practical exploit logic is entirely in the Python script; the HTML and README primarily document the vulnerability, affected endpoints, and disclosure context. The Python PoC is an asynchronous bulk credential-harvesting tool built with aiohttp and colorama. It reads target hosts from urls.txt (or a user-supplied file), then for each host constructs a base URL of the form http://<host>/wizard_page. It performs: (1) a GET to /wizard_pppoe_lua.lua to extract ADUsername and VDUsername from XML-like responses; (2) a GET to /wizard_wlan_config_lua.lua to extract the ESSID; and (3) a POST to /wizard_wlan_config_lua.lua with IF_ACTION=GetPassword, _InstID_PASS=DEV.WIFI.AP1.PSK1, and PASSTYPE=PSK to extract the Wi-Fi KeyPassphrase. Regex parsing is used to recover the values, and results are printed in a colored table. The script deduplicates identical result rows and suppresses per-host failures by returning blank fields. Main exploit capability: unauthenticated disclosure of sensitive router configuration data at scale. Although the repository frames the issue as an information leak that can lead to full admin compromise, the included code itself does not perform authentication bypass, configuration changes, command execution, or shell delivery. Instead, it operationalizes the information disclosure by harvesting PPPoE and WLAN credentials from multiple routers over HTTP. Because it actively retrieves secrets rather than merely checking exposure, this is a real exploit PoC rather than a pure detection script. Notable fingerprintable targets are the exposed wizard endpoints /wizard_page/wizard_pppoe_lua.lua and /wizard_page/wizard_wlan_config_lua.lua, plus the GetPassword action and associated POST parameters. The repository overall serves two purposes: a public-facing technical case study in index.html and a usable bulk PoC for extracting credentials from vulnerable ZTE routers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.