This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the credentials transmitted in plaintext.
Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unauthorized access to the targeted device.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda f3 Tenda n300 |
|
| Vendors & Products |
Tenda
Tenda f3 Tenda n300 |
Fri, 09 Jan 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cleartext Transmission Vulnerability in Tenda wireless routers | Cleartext Transmission Vulnerability in Tenda Wireless Routers |
Fri, 09 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the credentials transmitted in plaintext. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unauthorized access to the targeted device. | |
| Title | Cleartext Transmission Vulnerability in Tenda wireless routers | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published: 2026-01-09T11:02:50.926Z
Updated: 2026-01-09T15:15:27.815Z
Reserved: 2026-01-06T07:52:50.901Z
Link: CVE-2026-22079
Updated: 2026-01-09T15:15:23.369Z
Status : Received
Published: 2026-01-09T11:15:50.617
Modified: 2026-01-09T11:15:50.617
Link: CVE-2026-22079
No data.