CVE-2026-22081
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.38%
- CWE
- CWE-1004
- Published
- 2026-01-09
- Last modified
- 2026-03-12
Affected products
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
- Tenda 300Mbps Wireless Router F3 and N300 Easy Setup Router
Weakness type
Related vulnerabilities
- CVE-2026-82697 — sambitraj Student-Management-System session_start cookie httponly flag
- CVE-2026-21754 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2026-57948 — Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
- CVE-2026-11956 — TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
- CVE-2026-42239 — Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
- CVE-2026-39338 — ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration
- CVE-2026-35575 — ChurchCRM has Stored XSS in Group Name
- CVE-2026-25736 — Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute