CVE-2018-25317: Tenda a302 Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers.

Affected products

  • Tenda a302 Firmware: version 5.07.64_en only
  • Tenda w3002r Firmware: version 5.07.64_en only
  • Tenda w309r Firmware: version 5.07.64_en only

Published 2026-04-29. Last modified 2026-09-30.