CVE-2021-21735Disclosure(zte / zxhn_h168n)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch zte zxhn_h168n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0_EG1T4_TE.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-281

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zxhn_h168n
  • zxhn_h168n_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
zxhn_h168nzxhn_h168n_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1Mentions · 2026-05-31: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-31: 1Active Exploitation · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-31: 105-2505-2605-31
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-251
PoC1
2026-05-261
Disclosure1
2026-05-311
Disclosure1
Full discourse3 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/

    Post summary

    The post reports CVE‑2021‑21735 affecting ZTE H168N routers, revealing pre‑authentication PPPoE and WLAN secrets via an exposed wizard whitelist, and links to a blog post that likely contains a proof of concept.

    09039204.3K
    158.6K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    تم الكشف عن الثغرة CVE-2021-21735 في جهاز ZTE H168N، حيث تم تعريض قائمة السماح بالوصول لمعلومات PPPoE وWLAN قبل المصادقة. The security vulnerability CVE-2021-21735 has been identified in the ZTE H168N device, exposing the whitelist of PPPoE and WLAN secrets prior to authentication. https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/ #ZTE_H168N #CVE2021_21735 #Cybersecurity

    Post summary

    The tweet discloses CVE-2021-21735 in the ZTE H168N router, highlighting that it allows unauthenticated access to PPPoE/WLAN secrets, and provides a link for more details.

    00000246
    68 followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #NetSec #Threat_Research 1⃣. Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability // CVE-2026-5426 enabled RCE via shared ASPNET machine keys, leading to web shells, privilege escalation, and malware deployment, with mitigation requiring key rotation and vigilant monitoring 2⃣. Laravel Lang Packages Compromised https://socket.dev/blog/laravel-lang-compromise // Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets 3⃣. Google API keys keep working after you delete them https://www.aikido.dev/blog/google-api-keys-deletion // When you delete a Google API key, it says it’s immediately deleted. Our testing says ~23 min. During that window, an attacker with a leaked key keeps access to your data and enabled APIs 4⃣. Unauthenticated InfoLeak to Full Admin Compromise on ZTE ZXHN H168N https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/ // CVE-2021-21735 - critical flaw in ZTE routers allowing unauthenticated access to sensitive configuration data, enabling full device compromise and WLAN takeover 5⃣. Critical heap buffer overflow in 7-Zip https://thecybersecguru.com/exploits/cve-2026-48095-7-zip-heap-buffer-overflow/ // CVE-2026-48095

    Post summary

    The post announces several CVEs, providing technical details, exploitation evidence, and mitigation guidance, indicating a focus on disclosure.

    00000216
    3.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWztezxhn_h168n---
OSztezxhn_h168n_firmware---

Explore more