A vulnerability labeled as critical has been found in Tenda FH303 and A300 5.07.68_EN. This affects an unknown part of the file /goform/AdvSetDns. Such manipulation leads to authentication bypass by spoofing.

This vulnerability is referenced as CVE-2018-25318. It is possible to launch the attack remotely. Furthermore, an exploit is available.