Tenda F3 Wireless Router Clickjacking Vulnerability in Web Management Interface

Vulnerability

A clickjacking vulnerability has been identified in the web-based administrative interface of the Tenda F3 Wireless Router, specifically in firmware version 12.01.01.55_multi. The vulnerability arises because the interface does not include the X-Frame-Options header, which would prevent attacker-controlled sites from embedding administrative pages in an iframe. This omission can deceive an authenticated administrator into performing unintended actions that could lead to unauthorized changes in the router's configuration.

Impact

Exploitation of this vulnerability could allow an attacker to manipulate the router's administrative interface, potentially leading to unauthorized configuration changes.

Added: Feb 23, 2026, 5:31 PM
Updated: Feb 23, 2026, 6:38 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
5.2
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.