Stack-Based Buffer Overflow in Tenda 4G300 Router
CVE-2026-7470

8.7HIGH

Key Information:

Vendor

Tenda

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-7470?

A vulnerability exists in the Tenda 4G300 router specifically in the function sub_427C3C within the SafeMacFilter module. The flaw stems from improper handling of input data, which allows an attacker to exploit the stack, potentially leading to unauthorized memory access and execution of arbitrary code. This can be executed remotely, posing a serious risk to the security of affected devices. Users are advised to apply necessary mitigations and monitor for any unusual behavior.

Affected Version(s)

4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haaalion (VulDB User)
.