Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Tenda F3 Wireless Router Firmware Allows Malicious Script Execution

CVE-2026-27512
Summary

A security weakness in the Tenda F3 Wireless Router's administrative interface allows an attacker to inject malicious code that could be executed on the router, potentially giving them control over the device. This could lead to unauthorized access or changes to the router's settings. To fix this, update the router's firmware to the latest version available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda f3_firmware <= 12.01.01.55_multi
Original title
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff hea...
Original description
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.
nvd CVSS3.1 6.1
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-116
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026