Tenda
Tenda 4g300 Firmware: vulnerabilidades y CVE
Tenda 4g300 Firmware tiene 12 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses2
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-7470 | Alta (7.4) | 0.95% | — | 30 abr 2026 | A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow.… |
| CVE-2026-7469 | Baja (2.1) | 3.2% | — | 30 abr 2026 | A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The… |
| CVE-2024-4170 | Alta (8.8) | 1.7% | — | 25 abr 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429A30. The manipulation of the argument list1 leads to stack-based buffer overflow. The attack may be… |
| CVE-2024-4169 | Alta (8.8) | 1.8% | — | 25 abr 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the function sub_42775C/sub_4279CC. The manipulation of the argument page leads to stack-based buffer… |
| CVE-2024-4168 | Alta (8.8) | 1.8% | — | 25 abr 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been classified as critical. This affects the function sub_4260F0. The manipulation of the argument upfilen leads to stack-based buffer overflow. It is possible… |
| CVE-2024-4167 | Alta (8.8) | 1.8% | — | 25 abr 2024 | A vulnerability was found in Tenda 4G300 1.01.42 and classified as critical. Affected by this issue is the function sub_422AA4. The manipulation of the argument year/month/day/hour/minute/second leads to stack-based… |
| CVE-2024-4166 | Alta (8.8) | 1.8% | — | 25 abr 2024 | A vulnerability has been found in Tenda 4G300 1.01.42 and classified as critical. Affected by this vulnerability is the function sub_41E858. The manipulation of the argument GO/page leads to stack-based buffer overflow.… |
| CVE-2023-38929 | Crítica (9.8) | 0.84% | — | 7 ago 2023 | Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer. |
| CVE-2023-37723 | Crítica (9.8) | 0.93% | — | 14 jul 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting. |
| CVE-2023-37722 | Crítica (9.8) | 0.93% | — | 14 jul 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter. |
| CVE-2023-37721 | Crítica (9.8) | 0.93% | — | 14 jul 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter. |
| CVE-2023-37718 | Crítica (9.8) | 0.93% | — | 14 jul 2023 | Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.