CVE-2026-27514
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
23/02/2026
Last modified:
23/02/2026
Description
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:* | 12.01.01.55_multi (including) | |
| cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



