CVE-2026-27512

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-23 17:23

Updated : 2026-02-23 20:16


NVD link : CVE-2026-27512

Mitre link : CVE-2026-27512

CVE.ORG link : CVE-2026-27512


JSON object : View

Products Affected

tenda

  • f3_firmware
  • f3
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116

Improper Encoding or Escaping of Output