CVE-2018-25317: Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25317?
CVE-2018-25317 has a medium severity rating due to its potential to allow unauthorized modification of DNS settings.
How do I fix CVE-2018-25317?
To fix CVE-2018-25317, upgrade the firmware of your Tenda W3002R, A302, or W309R devices to the latest version beyond V5.07.64_en.
What are the affected versions for CVE-2018-25317?
Affected versions for CVE-2018-25317 include Tenda W3002R, A302, and W309R all running V5.07.64_en.
Who can exploit CVE-2018-25317?
CVE-2018-25317 can be exploited by unauthenticated attackers who can manipulate session cookies to change DNS settings.
What type of vulnerability is CVE-2018-25317?
CVE-2018-25317 is classified as a cookie session weakness which leads to improper session validation.