This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the Base64-encoded credentials.
Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unauthorized access to the targeted device.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda f3 Tenda n300 |
|
| Vendors & Products |
Tenda
Tenda f3 Tenda n300 |
Fri, 09 Jan 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Transmission Vulnerability in Tenda wireless routers | Insecure Transmission Vulnerability in Tenda Wireless Routers |
Fri, 09 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the Base64-encoded credentials. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unauthorized access to the targeted device. | |
| Title | Insecure Transmission Vulnerability in Tenda wireless routers | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published: 2026-01-09T11:05:07.368Z
Updated: 2026-01-09T15:12:48.077Z
Reserved: 2026-01-06T07:52:50.901Z
Link: CVE-2026-22080
Updated: 2026-01-09T15:12:43.670Z
Status : Received
Published: 2026-01-09T11:15:51.150
Modified: 2026-01-09T11:15:51.150
Link: CVE-2026-22080
No data.