Unrated severityNVD Advisory· Published Feb 23, 2026· Updated Mar 5, 2026
Tenda F3 Clickjacking in Web Management Interface
CVE-2026-27511
Description
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authenticated administrator into unintended interactions that may result in unauthorized configuration changes.
Affected products
2- Range: = firmware V12.01.01.55_multi
- Shenzhen Tenda Technology Co., Ltd./Tenda F3v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vulncheck.com/advisories/tenda-f3-clickjacking-in-web-management-interfacemitrethird-party-advisory
- www.tendacn.com/product/F3mitreproduct
News mentions
0No linked articles in our index yet.