PT-2026-21529 · Tenda · Tenda F3 Wireless Router
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Shenzhen Tenda F3 Wireless Router firmware version V12.01.01.55 multi
Description
The web-based administrative interface does not set the X-Frame-Options header, which allows an attacker to embed administrative pages in an iframe. This can trick an authenticated administrator into performing unintended actions, potentially leading to unauthorized configuration changes. This is a clickjacking issue.
Recommendations
Apply a configuration that sets the X-Frame-Options header to prevent embedding the administrative interface in an iframe.
Exploit
Correção
Clickjacking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tenda F3 Wireless Router