VYPR

F3 Firmware

by Tenda

CVEs (10)

  • CVE-2020-35391CriJan 1, 2021
    risk 0.68cvss 9.6epss 0.35

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either…

  • CVE-2026-27514MedFeb 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The…

  • CVE-2026-27512MedFeb 23, 2026
    risk 0.40cvss 6.1epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the…

  • CVE-2025-57573MedSep 10, 2025
    risk 0.36cvss 5.6epss 0.00

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.

  • CVE-2025-57572MedSep 10, 2025
    risk 0.36cvss 5.6epss 0.00

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.

  • CVE-2025-57571MedSep 10, 2025
    risk 0.36cvss 5.6epss 0.00

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.

  • CVE-2025-57570MedSep 10, 2025
    risk 0.36cvss 5.6epss 0.00

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.

  • CVE-2025-57569MedSep 10, 2025
    risk 0.36cvss 5.6epss 0.00

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.

  • CVE-2026-27513MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement anti-CSRF protections, allowing an attacker to induce an authenticated…

  • CVE-2026-27511MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe…