🔐 CVE Alert

CVE-2026-27511

MEDIUM 4.3

Tenda F3 Clickjacking in Web Management Interface

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authenticated administrator into unintended interactions that may result in unauthorized configuration changes.

CWE CWE-1021
Vendor shenzhen tenda technology co., ltd.
Product tenda f3
Published Feb 23, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for shenzhen tenda technology co., ltd. tenda f3

Be the first to know when new medium vulnerabilities affecting shenzhen tenda technology co., ltd. tenda f3 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Shenzhen Tenda Technology Co., Ltd. / Tenda F3
0 ≤ 12.01.01.55_multi

References

NVD ↗ CVE.org ↗ EPSS Data ↗
tendacn.com: https://www.tendacn.com/product/F3 vulncheck.com: https://www.vulncheck.com/advisories/tenda-f3-clickjacking-in-web-management-interface

Credits

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.