CVE-2026-27514

HIGH EPSS 12.0%
Published Feb 23, 20264mo ago · Modified Feb 23, 20264mo ago
7.1 CVSS 4.0
High
Find Similar
Published Feb 23, 2026 4mo ago
Last Modified Feb 23, 2026 4mo ago

Description

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.

CVSS Details

Base Score
7.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
12.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-201
CWE-525

Affected Products 2

VendorProductVersionRange
tendaf3_firmware* ≤12.01.01.55_multi
tendaf3*any

References 2

  • tendacn.com https://www.tendacn.com/product/F3
    Product
  • vulncheck.com https://www.vulncheck.com/advisories/tenda-f3-plaintext-credential-exposure-in-configuration-download
    Third Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.