Two high-severity vulnerabilities have been disclosed in Tenda router firmware, both affecting the SafeMacFilter functionality and both reported as remotely exploitable with public proof-of-concept code available. CVE-2026-7031 impacts Tenda F456 firmware 1.0.0.5, where the fromSafeMacFilter function in /goform/SafeMacFilter can be triggered into a buffer overflow by manipulating the page argument. The flaw was mapped to CWE-119 and CWE-120, with CVSS records indicating high impact on confidentiality, integrity, and availability.
A second issue, CVE-2026-7470, affects Tenda 4G300 firmware US_4G300V1.0Mt_V1.01.42_CN_TDC01 and involves a stack-based buffer overflow in the sub_427C3C function of the same /goform/SafeMacFilter component, again via the page parameter. The vulnerability was mapped to CWE-119 and CWE-121, and references for both disclosures point to VulDB entries, GitHub exploit material, and Tenda resources, indicating that multiple Tenda devices share a similar attack surface in SafeMacFilter request handling.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry for a remotely exploitable stack-based buffer overflow in the sub_427C3C function of Tenda 4G300 firmware US_4G300V1.0Mt_V1.01.42_CN_TDC01 was recorded. The issue affects the /goform/SafeMacFilter component through manipulation of the page argument, and the record cited VulDB, a GitHub proof-of-concept, and Tenda references.
A CVE entry for a remotely exploitable buffer overflow in the fromSafeMacFilter function of Tenda F456 firmware 1.0.0.5 was published. The flaw affects the /goform/SafeMacFilter component via manipulation of the page argument, and references included VulDB, a GitHub proof-of-concept, and Tenda.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.