CVE-2018-25317Disclosure(tenda / a302)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda a302 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a302
  • a302_firmware
  • w3002r
  • w3002r_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
a302a302_firmwarew3002rw3002r_firmwarew309rw309r_firmware

2 versions affected across 6 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-05-22: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-22: 104-2905-22
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-221
Patch1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2018-25317 (CVSS 9.8) Tenda W3002R/A302/W309R routers vulnerable to unauthenticated DNS hijacking via cookie session weakness. Attackers can redirect traffic to malicious DNS servers. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/6AUmkuzUd9

    Post summary

    The tweet warns about CVE‑2018‑25317, a critical DNS hijacking vulnerability affecting Tenda routers, and urges users to apply patches immediately.

    0000040
    30 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2018-25317 Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allow… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2018-25317 #Tenda #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2018-25317, a critical cookie session weakness in certain Tenda routers, notes a CVSS score of 9.8, and indicates no patch is currently available, linking to a detailed analysis.

    0000021
    208 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaa302---
OStendaa302_firmware5.07.64_en--
HWtendaw3002r---
OStendaw3002r_firmware5.07.64_en--
HWtendaw309r---
OStendaw309r_firmware5.07.64_en--

Explore more