Description

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.

INFO

Published Date :

2026-01-09T11:16:21.780Z

Last Modified :

2026-01-09T16:44:56.131Z

Source :

CERT-In
AFFECTED PRODUCTS

The following products are affected by CVE-2026-22081 vulnerability.

Vendors Products
Tenda
  • F3
  • N300
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-22081.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability