CVE-2018-25318
Received
Received - Intake
Session Weakness in Tenda FH303/A300 Firmware Allows DNS Hijacking
Publication date: 2026-04-29
Last updated on: 2026-05-04
Assigner: VulnCheck
Description
Description
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tenda | fh303_firmware | 5.07.68_en |
| tenda | a300_firmware | 5.07.68_en |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |