Description
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.
INFO
Published Date :
2026-01-09T11:16:21.780Z
Last Modified :
2026-01-09T16:44:56.131Z
Source :
CERT-In
AFFECTED PRODUCTS
The following products are affected by CVE-2026-22081 vulnerability.
| Vendors | Products |
|---|---|
| Tenda |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-22081.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability