8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Description
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection.
Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.
Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.
AI Analysis
Missing HTTPOnly flag for session cookies in Tenda wireless routers, allowing remote attackers to capture session cookies and gain unauthorized access.
Basic Information
ID
CVE-2026-22081
Source
CERT-In
Published
Jan 9, 2026 at 11:16
Affected Product
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Version
F3 v3.0 Firmware V12.01.01.41, F3 v3.0 Firmware V12.01.01.42, F3 v3.0 Firmware V12.01.01.48, F3 v3.0 Firmware V12.01.01.52, F3 v3.0 Firmware V12.01.01.55, F3 v4.0 Firmware V03.03.01.40
Affected Versions
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.41
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.42
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.48
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.52
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.55
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v4.0 Firmware V03.03.01.40
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.42
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.48
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.52
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v3.0 Firmware V12.01.01.55
Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router F3 v4.0 Firmware V03.03.01.40
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Version
F3 v3.0 Firmware V12.01.01.41, F3 v3.0 Firmware V12.01.01.42, F3 v3.0 Firmware V12.01.01.48, F3 v3.0 Firmware V12.01.01.52, F3 v3.0 Firmware V12.01.01.55, F3 v4.0 Firmware V03.03.01.40