CVE-2026-27512

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) El firmware V12.01.01.55_multi del Router inalámbrico Shenzhen Tenda F3 contiene una vulnerabilidad de confusión de tipo de contenido en la interfaz de administración. Las respuestas omiten el encabezado X-Content-Type-Options: nosniff e incluyen contenido influenciado por el atacante que puede ser reflejado en el cuerpo de la respuesta. Bajo comportamientos de navegador afectados, el sniffing de MIME puede hacer que la respuesta sea interpretada como HTML activo, permitiendo la ejecución de scripts en el contexto de la interfaz de administración.

23 Feb 2026, 20:16

Type Values Removed Values Added
References () https://www.tendacn.com/product/F3 - () https://www.tendacn.com/product/F3 - Product
References () https://www.vulncheck.com/advisories/tenda-f3-reflected-script-execution-via-missing-nosniff-header - () https://www.vulncheck.com/advisories/tenda-f3-reflected-script-execution-via-missing-nosniff-header - Third Party Advisory
CPE cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
First Time Tenda
Tenda f3
Tenda f3 Firmware

23 Feb 2026, 17:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 17:23

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27512

Mitre link : CVE-2026-27512

CVE.ORG link : CVE-2026-27512


JSON object : View

Products Affected

tenda

  • f3
  • f3_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116

Improper Encoding or Escaping of Output