CVE-2018-25318

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:fh303_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh303:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tenda:a300_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:a300:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-29 20:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25318

Mitre link : CVE-2018-25318

CVE.ORG link : CVE-2018-25318


JSON object : View

Products Affected

tenda

  • fh303_firmware
  • fh303
  • a300
  • a300_firmware
CWE
CWE-290

Authentication Bypass by Spoofing