CVE-2018-25318

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:fh303_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh303:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tenda:a300_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:a300:-:*:*:*:*:*:*:*

History

04 May 2026, 18:40

Type Values Removed Values Added
First Time Tenda fh303 Firmware
Tenda fh303
Tenda a300
Tenda
Tenda a300 Firmware
CPE cpe:2.3:h:tenda:fh303:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:a300_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh303_firmware:5.07.68_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:a300:-:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/44381 - () https://www.exploit-db.com/exploits/44381 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/tenda-fh303-a300-68-en-cookie-session-weakness-dns-change - () https://www.vulncheck.com/advisories/tenda-fh303-a300-68-en-cookie-session-weakness-dns-change - Third Party Advisory

30 Apr 2026, 15:11

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 20:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25318

Mitre link : CVE-2018-25318

CVE.ORG link : CVE-2018-25318


JSON object : View

Products Affected

tenda

  • fh303_firmware
  • a300_firmware
  • fh303
  • a300
CWE
CWE-290

Authentication Bypass by Spoofing