CVE-2026-7469

MEDIUM

Tenda 4G300 DelFil sub_425A28 command injection

Title source: cna
STIX 2.1

Description

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

Scores

CVSS v3 6.3
EPSS 0.0304
EPSS Percentile 86.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-77
Status published
Products (1)
Tenda/4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01
Published Apr 30, 2026
Tracked Since Apr 30, 2026