๐Ÿ” CVE Alert

CVE-2026-7469

MEDIUM 6.3

Tenda 4G300 DelFil sub_425A28 command injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

CWE CWE-77 CWE-74
Vendor tenda
Product 4g300
Published Apr 30, 2026
Stay Ahead of the Next One

Get instant alerts for tenda 4g300

Be the first to know when new medium vulnerabilities affecting tenda 4g300 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tenda / 4G300
US_4G300V1.0Mt_V1.01.42_CN_TDC01

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360205 vuldb.com: https://vuldb.com/vuln/360205/cti vuldb.com: https://vuldb.com/submit/804268 github.com: https://github.com/Axelioc/CVE/blob/main/Tenda/US_4G300/sub_425A28/sub_425A28.md tenda.com.cn: https://www.tenda.com.cn/

Credits

๐Ÿ” Haaalion (VulDB User)