Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 05 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda a302
Tenda a302 Firmware Tenda w3002r Firmware Tenda w309r Tenda w309r Firmware |
|
| CPEs | cpe:2.3:h:tenda:a302:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:w3002r:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:w309r:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:a302_firmware:5.07.64_en:*:*:*:*:*:*:* cpe:2.3:o:tenda:w3002r_firmware:5.07.64_en:*:*:*:*:*:*:* cpe:2.3:o:tenda:w309r_firmware:5.07.64_en:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda a302
Tenda a302 Firmware Tenda w3002r Firmware Tenda w309r Tenda w309r Firmware |
Thu, 30 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda w3002r |
|
| Vendors & Products |
Tenda
Tenda w3002r |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers. | |
| Title | Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-30T14:11:11.561Z
Reserved: 2026-04-29T12:27:08.662Z
Link: CVE-2018-25317
Updated: 2026-04-30T14:10:50.286Z
Status : Analyzed
Published: 2026-04-29T20:16:27.663
Modified: 2026-05-05T02:46:59.470
Link: CVE-2018-25317
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:20:34Z