Skip to content
CVSS 8.8 · HIGH

CVE-2026-7470

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

View on NVD

Analysis

This vulnerability affects specific firmware for the Tenda 4G300 router. Although it allows for remote execution via a stack-based buffer overflow, this consumer-grade networking hardware is not commonly used in professional development environments or infrastructure managed by the community. It represents vendor-specific firmware risk rather than a systemic risk to the software development ecosystem.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-119CWE-121

EPSS

Probability of exploitation (next 30 days): 0.0008 (0.1%)
Percentile: 23.1%
EPSS: 2026-05-06

Affects

tenda:4g300_firmwaretenda:4g300

Technical description

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: 4/30/2026, 3:16:01 AM
Last modified: 4/30/2026, 8:41:24 PM

References

HomeEventsBlogResourcesTeam