CVE-2026-34472 is an unauthenticated credential disclosure vulnerability affecting ZTE ZXHN H188A V6 routers running firmware versions V6.0.10P2_TE and V6.0.10P3N3_TE. A routing flaw in the web management interface allows unauthenticated requests to reach logic intended only for the pre-login setup wizard. The issue is attributed to improper handling of attacker-controlled request parameters in the router’s request-routing logic, which permits direct invocation of wizard handlers that should have been gated before authentication. Exposed handlers can return sensitive configuration data, including the default administrator password, WLAN credentials, and PPPoE credentials. Because the disclosed Wi-Fi password is also used as the default administrator password after uppercasing in observed cases, the information disclosure can directly enable authentication bypass. Some observations also indicate that certain configuration changes may be possible without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a public technical writeup plus a working Python PoC for CVE-2026-34472 affecting ZTE ZXHN H188A V6 firmware. The repo is small and straightforward: a static website (index.html, assets/site.css, assets/site.js, favicon.svg) presents the vulnerability details, while the actual exploit logic lives in poc/extract_wizard_credentials.py with supporting notes in poc/README.md and an example target list in poc/targets.txt.example. The exploit capability is unauthenticated credential extraction over the router web interface. The Python script iterates over supplied targets, tries HTTPS first and HTTP second, and sends three GET requests to the root path / with crafted query parameters that force routing into pre-login wizard handlers: IF_ACTION=getPassword, IF_ACTION=wlan_get, and IF_ACTION=ppp_get. Successful responses are parsed as JSON and the script extracts KeyPassphrase, ESSID, UserName, and any _sessionTOKEN value. The writeup explains that on validated devices the leaked Wi-Fi passphrase becomes the default administrator password after uppercasing, so the disclosure can directly enable authentication bypass to the admin interface. The exploit is operational but limited in scope: it does not automate login or configuration changes, and it does not exercise the broader write-capable authorization failure mentioned in the documentation. Still, it is more than a detector because it actively retrieves sensitive secrets from vulnerable devices. The attack vector is web/network-based and requires only reachability to the management interface; no prior authentication is needed. Notable fingerprintable targets and observables include the root web endpoint on the target device, the query parameters _type=tedataNotLoginData and _tag=wizard_lua.lua, and the specific IF_ACTION values getPassword, wlan_get, and ppp_get. These are strong indicators of attempted exploitation or validation of this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.