CVE-2022-25172
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-1004
- Published
- 2022-05-12
- Last modified
- 2026-03-13
Affected products
- InHand Networks InRouter302
Weakness type
Related vulnerabilities
- CVE-2026-22081 — Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routers
- CVE-2025-53757 — Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Router
- CVE-2025-0479 — Security Misconfiguration Vulnerability in CP Plus Router
- CVE-2021-42115 — Missing HTTPOnly flag on sensitive cookie in TopEase
- CVE-2026-25136 — Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
- CVE-2022-21939 — Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)
- CVE-2021-3706 — Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte
- CVE-2026-25733 — Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function