{"id":"CVE-2018-25317","title":"Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation","summary":"Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send G…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-290"],"vendor":"tenda","product":"w309r_firmware","affected":["w309r_firmware = 5.07.64_en","a302_firmware = 5.07.64_en","w3002r_firmware = 5.07.64_en"],"published":"2026-04-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:17:51.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-25317","references":[{"url":"https://www.exploit-db.com/exploits/44380","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tenda-w3002r-a302-w309r-64-en-cookie-session-weakness-dns-change","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00651,"epssPercentile":0.4925,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-04-30T14:08:46.216555Z"},"ingestedAt":"2026-09-30T18:17:24.569Z","slug":"CVE-2018-25317","body":"## Overview\n\nTenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers.\n\n## Affected\n\n- `w309r_firmware = 5.07.64_en`\n- `a302_firmware = 5.07.64_en`\n- `w3002r_firmware = 5.07.64_en`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}