This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session ID during insecure transmission.
Successful exploitation of this vulnerability could allow the attacker to hijack an authenticated session and compromise sensitive configuration information on the targeted device.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda f3 Tenda n300 |
|
| Vendors & Products |
Tenda
Tenda f3 Tenda n300 |
Fri, 09 Jan 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session ID during insecure transmission. Successful exploitation of this vulnerability could allow the attacker to hijack an authenticated session and compromise sensitive configuration information on the targeted device. | |
| Title | Insecure Session ID Management Vulnerability in Tenda Wireless Routers | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-01-09T16:26:14.019Z
Reserved: 2026-01-06T07:52:50.901Z
Link: CVE-2026-22082
Updated: 2026-01-09T16:26:05.793Z
Status : Received
Published: 2026-01-09T12:15:54.403
Modified: 2026-01-09T12:15:54.403
Link: CVE-2026-22082
No data.
OpenCVE Enrichment
Updated: 2026-01-09T13:23:27Z