PT-2025-14776 · Tenda · Tenda Ac23

Li Zhiyang

·

Published

2025-04-03

·

Updated

2025-04-03

·

CVE-2025-3167

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC23 version 16.03.07.52
Description A problematic issue has been found in the API Interface component, affecting the processing of the file /goform/VerAPIMant. The manipulation of the getuid argument leads to denial of service. This issue can be exploited remotely.
Recommendations For Tenda AC23 version 16.03.07.52, as a temporary workaround, consider restricting access to the /goform/VerAPIMant API endpoint to minimize the risk of exploitation. Avoid using the getuid argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2025-3167

Affected Products

Tenda Ac23