Description

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.

INFO

Published Date :

2026-02-23T16:27:38.171Z

Last Modified :

2026-02-23T18:31:35.987Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2026-27514 vulnerability.

Vendors Products
Tenda
  • F3
  • F3 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-27514.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact