
CVE-2021-21735: ZTE H168N Router Vulnerability Exposes PPPoE and WLAN Secrets
CybersecurityVulnerabilitiesNetworkSecurityRouterSecurity
The vulnerability affects the ZTE ZXHN H168N V3.5 router and involves an information disclosure issue due to an authorization failure. Unauthenticated access to wizard handlers under the setup interface exposed sensitive PPPoE and WLAN configuration details. The flaw stems from a flawed whitelist mechanism in the QuickSetup flow, specifically affecting routes like wizard_pppoe_lua.lua and wizard_wlan_config_lua.lua.