CVE-2026-22081
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-09

Last updated on: 2026-01-09

Assigner: Indian Computer Emergency Response Team (CERT-In)

Description
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-09
Last Modified
2026-01-09
Generated
2026-05-07
AI Q&A
2026-01-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tenda wired_router_f3 *
tenda wired_router_n300_easy_setup *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1004 The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in certain Tenda wireless routers because the session cookies used by the web-based administrative interface lack the HTTPOnly flag. This means that an attacker could capture these session cookies if they intercept the HTTP traffic, potentially allowing them to hijack the session and gain unauthorized access to the router's administrative functions.


How can this vulnerability impact me? :

If exploited, this vulnerability could allow an attacker to obtain sensitive information by capturing session cookies and gain unauthorized access to the targeted Tenda wireless router. This could lead to control over the device, potentially compromising network security and privacy.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart