PatchSiren cyber security CVE debrief
CVE-2018-25317 Tenda CVE debrief
The CVE-2018-25317 vulnerability is a critical cookie session weakness in Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en. This vulnerability allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Defenders responsible for these routers should assess exposure and prioritize verifying DNS settings and validating session cookies. The CVE record was published on 2026-04-29T20:16:27.663Z and has not been modified since then. To address this vulnerability, defenders should focus on validating firmware versions and configuration settings to ensure exposure. The vulnerability requires immediate attention to DNS
- Vendor
- Tenda
- Product
- W3002R
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-29
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-29
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en should assess exposure and prioritize verifying DNS settings and validating session cookies.
Why it matters
CVE-2018-25317 is a critical vulnerability in Tenda W3002R/A302/W309R wireless routers that allows unauthenticated attackers to modify DNS settings. Defenders should prioritize verifying DNS settings and validating session cookies to prevent exploitation. The vulnerability requires validation of firmware versions and configuration settings to ensure exposure.
- Unauthenticated attackers can modify DNS settings, potentially redirecting user traffic to malicious DNS servers.
- Defenders need to verify DNS settings and validate session cookies to prevent exploitation.
- The vulnerability requires validation of firmware versions and configuration settings to ensure exposure.
Technical summary
Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en are vulnerable to a cookie session weakness that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. This vulnerability requires validation of firmware versions and configuration settings to ensure exposure. The vulnerability allows attackers to send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers. Defenders should prioritize verifying DNS settings and validating session cookies to prevent exploitation.
Defensive priority
Defenders should prioritize verifying DNS settings and validating session cookies for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.
Recommended defensive actions
- Verify DNS settings for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.
- Validate session cookies for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.
- Update firmware to a version that addresses the cookie session weakness vulnerability, if available.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the cookie session weakness vulnerability in Tenda W3002R/A302/W309R wireless routers. However, the corpus does not establish versions beyond V5.07.64_en or provide evidence of exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-25317 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-25317
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-25317 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-25317
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/44380
[email protected] - Exploit, Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/tenda-w3002r-a302-w309r-64-en-cookie-session-weakness-dns-change
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.