← Back

F3 Firmware

f3_firmware

Vendor: Tenda • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1F3 Firmware
Jun 17, 2026
Feb 23, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router p...Show more
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.Show less
1Tenda
1F3 Firmware
Jun 17, 2026
Feb 23, 2026
5.1 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement anti-CSRF protections,...Show more
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement anti-CSRF protections, allowing an attacker to induce an authenticated administrator to submit state-changing requests, which can result in unauthorized configuration changes.Show less
1Tenda
1F3 Firmware
Jun 17, 2026
Feb 23, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacke...Show more
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the response body. Under affected browser behaviors, MIME sniffing may cause the response to be interpreted as active HTML, enabling script execution in the context of the administrative interface.Show less
1Tenda
1F3 Firmware
Jun 17, 2026
Feb 23, 2026
5.1 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-cont...Show more
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based administrative interface. The interface does not set the X-Frame-Options header, allowing attacker-controlled sites to embed administrative pages in an iframe and trick an authenticated administrator into unintended interactions that may result in unauthorized configuration changes.Show less
1Tenda
1F3 Firmware
Jul 5, 2026
Sep 10, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.
1Tenda
1F3 Firmware
Jul 5, 2026
Sep 10, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.
1Tenda
1F3 Firmware
Jul 5, 2026
Sep 10, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.
1Tenda
1F3 Firmware
Jul 5, 2026
Sep 10, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.
1Tenda
1F3 Firmware
Jul 5, 2026
Sep 10, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.
1Tenda
1F3 Firmware
Jun 17, 2026
Jan 1, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14...Show more
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.Show less