Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda f3 Tenda f3 Firmware |
|
| CPEs | cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda f3 Tenda f3 Firmware |
Mon, 23 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data. | |
| Title | Tenda F3 Plaintext Credential Exposure in Configuration Download | |
| Weaknesses | CWE-201 CWE-525 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T23:11:27.235Z
Reserved: 2026-02-19T19:51:07.328Z
Link: CVE-2026-27514
Updated: 2026-02-23T18:30:37.444Z
Status : Analyzed
Published: 2026-02-23T17:23:30.087
Modified: 2026-02-23T20:11:48.337
Link: CVE-2026-27514
No data.
OpenCVE Enrichment
Updated: 2026-04-17T16:30:05Z