CVE-2026-7469: Tenda 4G300 DelFil sub_425A28 command injection
A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7469?
CVE-2026-7469 is classified as a high-severity vulnerability due to its potential for remote command injection.
How can I fix CVE-2026-7469?
To mitigate CVE-2026-7469, it is recommended to update the Tenda 4G300 device to the latest firmware version provided by the vendor.
What impact does CVE-2026-7469 have on the Tenda 4G300?
CVE-2026-7469 allows an attacker to execute arbitrary commands on the Tenda 4G300 device via a specially crafted request.
Is CVE-2026-7469 a remote vulnerability?
Yes, CVE-2026-7469 can be exploited remotely over the network.
Which version of Tenda 4G300 is affected by CVE-2026-7469?
CVE-2026-7469 affects Tenda 4G300 with the firmware version US_4G300V1.0Mt_V1.01.42_CN_TDC01.