Description
A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-29: | Advisory disclosed |
| 2026-04-29: | VulDB entry created |
| 2026-04-29: | VulDB entry last update |
Credits
Haaalion (VulDB User)
References
vuldb.com/vuln/360205 (VDB-360205 | Tenda 4G300 DelFil sub_425A28 command injection)
vuldb.com/vuln/360205/cti (VDB-360205 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/804268 (Submit #804268 | Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01 Command Injection)
github.com/...b/main/Tenda/US_4G300/sub_425A28/sub_425A28.md
www.tenda.com.cn/