Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Tenda F3 Wireless Router Can Be Tricked into Unwanted Configuration Changes

CVE-2026-27511
Summary

A security weakness in the Tenda F3 Wireless Router's web interface allows an attacker to trick an administrator into making unintended changes to the router's settings. This could lead to unauthorized access or changes to the network. The router's manufacturer should be contacted to obtain a patched version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda f3_firmware <= 12.01.01.55_multi
Original title
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header,...
Original description
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authenticated administrator into unintended interactions that may result in unauthorized configuration changes.
nvd CVSS3.1 4.3
nvd CVSS4.0 5.1
Vulnerability type
CWE-1021
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026