


Perceptive Security
SOC/SIEM Consultancy

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insuf…
Published:
28 april 2026 om 22:00:00
Alert date:
29 april 2026 om 21:06:00
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
CVE-2018-25318 affects Tenda FH303/A300 firmware V5.07.68_EN with a session weakness vulnerability. The flaw allows unauthenticated attackers to modify DNS settings through insufficient cookie validation. Attackers can exploit the /goform/AdvSetDns endpoint by sending GET requests with crafted admin cookies. This vulnerability enables DNS hijacking attacks to redirect user traffic to malicious sites. The weakness stems from inadequate session management and authentication controls in the router firmware.
Technical details
Mitigation steps:
Affected products:
Tenda FH303
Tenda A300
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25318
https://www.exploit-db.com/exploits/44381
https://www.vulncheck.com/advisories/tenda-fh303-a300-68-en-cookie-session-weakness-dns-change
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
