CVE-2025-3167 is a denial-of-service vulnerability affecting Tenda AC23 routers running firmware version 16.03.07.52. An unauthenticated remote attacker can trigger this vulnerability by manipulating the 'getuid' argument within the /goform/VerAPIMant API interface. This flaw carries a CVSS v3.1 score of 7.5 (HIGH), indicating a high impact on availability with low attack complexity and no user interaction required. While public exploit details exist, there is no evidence of active exploitation, nor is there significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.03.07.52CPE matchmatch criteria | cpe:2.3:o:tenda:ac23_firmware:16.03.07.52:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.