VYPR
Medium severity6.1NVD Advisory· Published Feb 23, 2026· Updated Jun 17, 2026

CVE-2026-27512

CVE-2026-27512

Description

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Range: V12.01.01.55_multi
  • Tenda/F3llm-fuzzy
    Range: V12.01.01.55_multi
  • Shenzhen Tenda Technology Co., Ltd./Tenda F3v5
    Range: 0
  • cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:*
    Range: <=12.01.01.55_multi

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.