CVE-2026-27514 describes a sensitive information exposure vulnerability in the configuration download functionality of Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi. This flaw allows an authenticated attacker to retrieve the router and administrative passwords in plaintext, as the configuration download response lacks proper Cache-Control directives, potentially exposing credentials through client-side caches. Rated with a CVSS score of 6.5 (Medium), the vulnerability has a network attack vector and low attack complexity, meaning an attacker with legitimate access to the router's web interface can easily exploit it to gain full administrative control. The primary impact is high confidentiality, as sensitive authentication data is exposed. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.01.01.55_multiCPE matchmatch criteria | cpe:2.3:o:tenda:f3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.