Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda w308r Firmware
|
|
| CPEs | cpe:2.3:h:tenda:w308r:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:w308r_firmware:5.07.48:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda w308r Firmware
|
Thu, 30 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda w308r |
|
| Vendors & Products |
Tenda
Tenda w308r |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS servers and redirect user traffic to malicious sites. | |
| Title | Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-30T12:39:23.647Z
Reserved: 2026-04-29T12:26:39.586Z
Link: CVE-2018-25316
Updated: 2026-04-30T12:39:12.792Z
Status : Analyzed
Published: 2026-04-29T20:16:27.503
Modified: 2026-05-04T18:42:37.520
Link: CVE-2018-25316
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:20:36Z