CVE-2026-27514: Tenda F3 Plaintext Credential Exposure in Configuration Download
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The endpoint also omits appropriate Cache-Control directives, which can allow the response to be stored in client-side caches and recovered by other local users or processes with access to cached browser data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27514?
CVE-2026-27514 is classified as a high-severity vulnerability due to the exposure of plaintext administrative credentials.
How do I fix CVE-2026-27514?
To remediate CVE-2026-27514, update your Shenzhen Tenda F3 Wireless Router firmware to the latest version provided by the manufacturer.
What kind of information is exposed in CVE-2026-27514?
CVE-2026-27514 exposes sensitive information, including the router and administrative passwords in plaintext.
Who is affected by CVE-2026-27514?
Users of Shenzhen Tenda F3 Wireless Router with firmware version V12.01.01.55_multi are affected by CVE-2026-27514.
Is CVE-2026-27514 easy to exploit?
Yes, CVE-2026-27514 can be easily exploited if proper security measures are not taken to protect the router's configuration files.