CVE-2026-27512
Tenda F3 Reflected Script Execution via Missing nosniff Header
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.
| CWE | CWE-79 CWE-116 |
| Vendor | shenzhen tenda technology co., ltd. |
| Product | tenda f3 |
| Published | Feb 23, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for shenzhen tenda technology co., ltd. tenda f3
Be the first to know when new medium vulnerabilities affecting shenzhen tenda technology co., ltd. tenda f3 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Shenzhen Tenda Technology Co., Ltd. / Tenda F3
0 ≤ 12.01.01.55_multi
References
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.