CVE Database
/

CVE-2026-22081

Back to search

CVE-2026-22081

Published: Jan 9, 2026

Modified: Jan 9, 2026

PUBLISHED

Description

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.

VendorProductVersions

Tenda

300Mbps Wireless Router F3 and N300 Easy Setup Router

affected
F3 v3.0 Firmware V12.01.01.41
affected
F3 v3.0 Firmware V12.01.01.42
affected
F3 v3.0 Firmware V12.01.01.48
affected
F3 v3.0 Firmware V12.01.01.52
affected
F3 v3.0 Firmware V12.01.01.55

+1 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now