<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CVE-2026-34474: Pre-auth #credential disclosure in #ZTE #H298A &#x2F; #H108N via #ETHCheat...The short version: an ETHCheat branch returns credential-bearing #HTML before #authentication.]]></title><description><![CDATA[<p>CVE-2026-34474: Pre-auth <a href="https://mstdn.ca/tags/credential" rel="tag">#<span>credential</span></a> disclosure in <a href="https://mstdn.ca/tags/ZTE" rel="tag">#<span>ZTE</span></a> <a href="https://mstdn.ca/tags/H298A" rel="tag">#<span>H298A</span></a> / <a href="https://mstdn.ca/tags/H108N" rel="tag">#<span>H108N</span></a> via <a href="https://mstdn.ca/tags/ETHCheat" rel="tag">#<span>ETHCheat</span></a>...The short version: an ETHCheat branch returns credential-bearing <a href="https://mstdn.ca/tags/HTML" rel="tag">#<span>HTML</span></a> before <a href="https://mstdn.ca/tags/authentication" rel="tag">#<span>authentication</span></a>. The captured fields include the admin password, WLAN PSK, and ESSID, and a companion wizard <a href="https://mstdn.ca/tags/endpoint" rel="tag">#<span>endpoint</span></a> <a href="https://mstdn.ca/tags/exposes" rel="tag">#<span>exposes</span></a> serial data. </p><p><a href="https://mstdn.ca/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://mstdn.ca/tags/cybersec" rel="tag">#<span>cybersec</span></a> <a href="https://mstdn.ca/tags/security" rel="tag">#<span>security</span></a> <a href="https://mstdn.ca/tags/exploited" rel="tag">#<span>exploited</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://cdn.mstdn.ca/media_attachments/files/116/625/895/059/997/300/original/43a99e07476b4308.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/e83062d8-3604-4773-9038-61de289e9df7/cve-2026-34474-pre-auth-credential-disclosure-in-zte-h298a-h108n-via-ethcheat...the-short-version-an-ethcheat-branch-returns-credential-bearing-html-before-authentication.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 05:37:04 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/e83062d8-3604-4773-9038-61de289e9df7.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 23 May 2026 20:59:54 GMT</pubDate><ttl>60</ttl></channel></rss>