Tenda Wireless Routers Insecure Transmission of Credentials Vulnerability

Vulnerability

A vulnerability exists in Tenda wireless routers, specifically the 300Mbps Wireless Router F3 and the N300 Easy Setup Router, due to the transmission of credentials encoded in reversible Base64 through the web-based administrative interface. This flaw allows an attacker on the same network to intercept and decode the Base64-encoded credentials, potentially leading to unauthorized access to the device.

Impact

Exploitation of this vulnerability could result in the unauthorized access to the affected router, allowing an attacker to compromise sensitive configuration information.

Remediation

Users are advised to apply the updates mentioned by the vendor. For more information, visit the Tenda India website.

Added: Jan 9, 2026, 11:18 AM
Updated: Jan 9, 2026, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
1.3
exploitability
4.5
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.