CVE-2026-27512

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:*

History

23 Feb 2026, 20:16

Type Values Removed Values Added
References () https://www.tendacn.com/product/F3 - () https://www.tendacn.com/product/F3 - Product
References () https://www.vulncheck.com/advisories/tenda-f3-reflected-script-execution-via-missing-nosniff-header - () https://www.vulncheck.com/advisories/tenda-f3-reflected-script-execution-via-missing-nosniff-header - Third Party Advisory
CPE cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
First Time Tenda
Tenda f3
Tenda f3 Firmware

23 Feb 2026, 17:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 17:23

Updated : 2026-02-23 20:16


NVD link : CVE-2026-27512

Mitre link : CVE-2026-27512

CVE.ORG link : CVE-2026-27512


JSON object : View

Products Affected

tenda

  • f3
  • f3_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116

Improper Encoding or Escaping of Output