Vulnerability record · CVE-2018-7358 · published 14 November 2018
CVE-2018-7358: ZTE ZXHN H168N router improper authentication allows unauthorized operations
Zte · Zxhn H168n Firmware
ZTE ZXHN H168N firmware versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T contain an improper change control flaw mapped to CWE-287 (improper authentication). An unauthorized user can perform operations that should require authentication, giving full control over confidentiality, integrity and availability of the device.
Description
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no authentication or user interaction required, public exploit code available, and very high EPSS, though exploitation is limited to adjacent network access.
What it is
ZTE ZXHN H168N firmware versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T contain an improper change control flaw mapped to CWE-287 (improper authentication). An unauthorized user can perform operations that should require authentication, giving full control over confidentiality, integrity and availability of the device.
Impact
An attacker on the adjacent network can perform unauthorized operations on the router, with high impact to confidentiality, integrity and availability. This can lead to full device compromise, including configuration changes and traffic manipulation.
Attack surface
The CVSS vector AV:A/PR:N/UI:N indicates the flaw is reachable from an adjacent network segment with no authentication and no user interaction. No remote-internet vector or specific exposed interface is stated in the record.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.89645, 99.78th percentile) and a public Exploit-DB entry (45972) exists, indicating exploit code is publicly available. No ransomware usage is documented.
What to do
- Apply the vendor firmware update from the ZTE advisory (newsId=1009523) for the affected ZXHN H168N versions.
- If patching is not possible, restrict the router's management and LAN-side exposure to trusted segments and disable remote administration.
- Segment or isolate the router from untrusted adjacent networks and place it behind a firewall with strict access rules.
- Replace end-of-life or unpatchable units with supported hardware.
- Monitor vendor advisories for updated firmware since the record does not list fixed versions.
Detection
- Review router logs for configuration changes or administrative actions from unexpected source addresses.
- Alert on access to management interfaces from hosts outside the expected admin subnet.
- Compare running configuration against a known-good baseline to catch unauthorized changes.
- Monitor network traffic for known exploit patterns against ZXHN H168N management services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1009523 | Vendor Advisory |
| http://www.securityfocus.com/bid/105963 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45972/ | ExploitThird Party AdvisoryVDB Entry |
| http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1009523 | Vendor Advisory |
| http://www.securityfocus.com/bid/105963 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45972/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-7358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-7358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.