Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch zte zxhn_h168n systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0_EG1T4_TE.
The post reports CVE‑2021‑21735 affecting ZTE H168N routers, revealing pre‑authentication PPPoE and WLAN secrets via an exposed wizard whitelist, and links to a blog post that likely contains a proof of concept.
تم الكشف عن الثغرة CVE-2021-21735 في جهاز ZTE H168N، حيث تم تعريض قائمة السماح بالوصول لمعلومات PPPoE وWLAN قبل المصادقة.
The security vulnerability CVE-2021-21735 has been identified in the ZTE H168N device, exposing the whitelist of PPPoE and WLAN secrets prior to authentication. https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/
#ZTE_H168N#CVE2021_21735#Cybersecurity
Post summary
The tweet discloses CVE-2021-21735 in the ZTE H168N router, highlighting that it allows unauthenticated access to PPPoE/WLAN secrets, and provides a link for more details.
#NetSec#Threat_Research
1⃣. Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability
// CVE-2026-5426 enabled RCE via shared ASPNET machine keys, leading to web shells, privilege escalation, and malware deployment, with mitigation requiring key rotation and vigilant monitoring
2⃣. Laravel Lang Packages Compromised https://socket.dev/blog/laravel-lang-compromise
// Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets
3⃣. Google API keys keep working after you delete them https://www.aikido.dev/blog/google-api-keys-deletion
// When you delete a Google API key, it says it’s immediately deleted. Our testing says ~23 min. During that window, an attacker with a leaked key keeps access to your data and enabled APIs
4⃣. Unauthenticated InfoLeak to Full Admin Compromise on ZTE ZXHN H168N https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/
// CVE-2021-21735 - critical flaw in ZTE routers allowing unauthenticated access to sensitive configuration data, enabling full device compromise and WLAN takeover
5⃣. Critical heap buffer overflow in 7-Zip https://thecybersecguru.com/exploits/cve-2026-48095-7-zip-heap-buffer-overflow/
// CVE-2026-48095
Post summary
The post announces several CVEs, providing technical details, exploitation evidence, and mitigation guidance, indicating a focus on disclosure.