← Vulnerability feed

Vulnerability record · CVE-2018-7358 · published 14 November 2018

CVE-2018-7358: ZTE ZXHN H168N router improper authentication allows unauthorized operations

Zte · Zxhn H168n Firmware

ZTE ZXHN H168N firmware versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T contain an improper change control flaw mapped to CWE-287 (improper authentication). An unauthorized user can perform operations that should require authentication, giving full control over confidentiality, integrity and availability of the device.

8.8 CVSS 3.0 High EPSS 90% · top 0.2% CWE-287 · Improper authentication
8.8CVSS 3.0 base score, v2 5.8
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no authentication or user interaction required, public exploit code available, and very high EPSS, though exploitation is limited to adjacent network access.

What it is

ZTE ZXHN H168N firmware versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T contain an improper change control flaw mapped to CWE-287 (improper authentication). An unauthorized user can perform operations that should require authentication, giving full control over confidentiality, integrity and availability of the device.

Impact

An attacker on the adjacent network can perform unauthorized operations on the router, with high impact to confidentiality, integrity and availability. This can lead to full device compromise, including configuration changes and traffic manipulation.

Attack surface

The CVSS vector AV:A/PR:N/UI:N indicates the flaw is reachable from an adjacent network segment with no authentication and no user interaction. No remote-internet vector or specific exposed interface is stated in the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.89645, 99.78th percentile) and a public Exploit-DB entry (45972) exists, indicating exploit code is publicly available. No ransomware usage is documented.

What to do

  • Apply the vendor firmware update from the ZTE advisory (newsId=1009523) for the affected ZXHN H168N versions.
  • If patching is not possible, restrict the router's management and LAN-side exposure to trusted segments and disable remote administration.
  • Segment or isolate the router from untrusted adjacent networks and place it behind a firewall with strict access rules.
  • Replace end-of-life or unpatchable units with supported hardware.
  • Monitor vendor advisories for updated firmware since the record does not list fixed versions.

Detection

  • Review router logs for configuration changes or administrative actions from unexpected source addresses.
  • Alert on access to management interfaces from hosts outside the expected admin subnet.
  • Compare running configuration against a known-good baseline to catch unauthorized changes.
  • Monitor network traffic for known exploit patterns against ZXHN H168N management services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21730Zte zxhn h168n firmware vulnerabilityA ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attack…EPSS 1.0%8.8CVE-2018-7357ZTE ZXHN H168N router missing authentication for critical functionZTE ZXHN H168N firmware versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T expose a critical function without authentication (CW…EPSS 88%analysed6.5CVE-2021-21735Zte zxhn h168n firmware vulnerabilityA ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit th…EPSS 0.93%6.5CVE-2021-21729Zte zxhn h168n firmware cross-site request forgery vulnerabilitySome ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization oper…EPSS 0.38%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2018-7358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.