PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-25317 Tenda CVE debrief

The CVE-2018-25317 vulnerability is a critical cookie session weakness in Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en. This vulnerability allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Defenders responsible for these routers should assess exposure and prioritize verifying DNS settings and validating session cookies. The CVE record was published on 2026-04-29T20:16:27.663Z and has not been modified since then. To address this vulnerability, defenders should focus on validating firmware versions and configuration settings to ensure exposure. The vulnerability requires immediate attention to DNS

Vendor
Tenda
Product
W3002R
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-29
Original CVE updated
2026-09-30
Advisory published
2026-04-29
Advisory updated
2026-09-30

Who should care

Defenders responsible for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en should assess exposure and prioritize verifying DNS settings and validating session cookies.

Why it matters

CVE-2018-25317 is a critical vulnerability in Tenda W3002R/A302/W309R wireless routers that allows unauthenticated attackers to modify DNS settings. Defenders should prioritize verifying DNS settings and validating session cookies to prevent exploitation. The vulnerability requires validation of firmware versions and configuration settings to ensure exposure.

  • Unauthenticated attackers can modify DNS settings, potentially redirecting user traffic to malicious DNS servers.
  • Defenders need to verify DNS settings and validate session cookies to prevent exploitation.
  • The vulnerability requires validation of firmware versions and configuration settings to ensure exposure.

Technical summary

Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en are vulnerable to a cookie session weakness that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. This vulnerability requires validation of firmware versions and configuration settings to ensure exposure. The vulnerability allows attackers to send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers. Defenders should prioritize verifying DNS settings and validating session cookies to prevent exploitation.

Defensive priority

Defenders should prioritize verifying DNS settings and validating session cookies for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.

Recommended defensive actions

  • Verify DNS settings for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.
  • Validate session cookies for Tenda W3002R/A302/W309R wireless routers running firmware version V5.07.64_en.
  • Update firmware to a version that addresses the cookie session weakness vulnerability, if available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the cookie session weakness vulnerability in Tenda W3002R/A302/W309R wireless routers. However, the corpus does not establish versions beyond V5.07.64_en or provide evidence of exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-25317 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-25317

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-25317 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-25317

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.exploit-db.com/exploits/44380

    [email protected] - Exploit, Third Party Advisory, VDB Entry

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/tenda-w3002r-a302-w309r-64-en-cookie-session-weakness-dns-change

    [email protected] - Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.