Tenda Vulnerabilities
Comprehensive security vulnerability database for Tenda products
4
1
34
5
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-27513 | 5.1 | An attacker can trick an authenticated administrator of the Tenda F3 router into making unwanted changes to the router's settings through its web interface. This vulnerability occurs because the router does not have protections in place to prevent such attacks, meaning the administrator must be logged in for the attack to succeed. | tendaf3 firmware | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2026-27512 | 5.1 | This vulnerability allows an attacker to execute malicious scripts within the administrative interface of the Tenda F3 router, potentially gaining control over the device. It occurs because the router's firmware does not properly handle content types, which can lead to browsers interpreting harmful content as legitimate HTML, but it requires the attacker to trick the router into sending a specially crafted response. | tendaf3 firmware | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2026-27511 | 5.1 | This vulnerability allows an attacker to trick an authenticated administrator into making unwanted changes to the router's settings by embedding the router's admin page in a hidden frame on their own website. It requires the administrator to visit the attacker's site while logged into the router's interface, as the router does not protect its pages from being embedded in this way. | tendaf3 firmware | Theoretical | about 1 month agoFeb 23, 2026 |
| CVE-2026-2930 | 5.3 | This vulnerability allows an attacker to remotely execute code on Tenda A18 routers by exploiting a flaw in the file upload function, which can lead to a stack-based buffer overflow. To successfully carry out the attack, the attacker needs to manipulate specific input parameters, and there are already publicly available methods to exploit this weakness. | tendaa18 firmware | Exploit Available | about 1 month agoFeb 22, 2026 |
About Tenda Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Tenda products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.