- Firmware download website: https://www.tenda.com.cn/download/detail-2227.html
4G300 V1.01.42
The Tenda 4G300 V1.01.42 firmware has a stack overflow vulnerability in the sub_429A30
function. The v4
variable receives the list1
parameter from a POST request. However, since the user can control the input of list1
, the statement can cause a buffer overflow. The user-provided list1
can exceed the capacity of the v15
array, triggering this security vulnerability.