CyberRota
Back to database

CVE-2018-25318

CRITICAL · CVSS 9.8 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-29 · Last synced: 2026-05-29

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-25318
Severity
CRITICAL
CVSS
9.8
EPSS
0.16%

Original NVD Description

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.