cbcvebase.
CVE-2025-8160
published 2025-07-25

CVE-2025-8160: A vulnerability classified as critical has been found in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/SetSysTimeCfg of the…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.24%
65.9th percentile
A vulnerability classified as critical has been found in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/SetSysTimeCfg of the component httpd. The manipulation of the argument timeZone leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Affected

14 ranges
VendorProductVersion rangeFixed in
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/goform/SetSysTimeCfg
path/goform/SetSysTimeCfg
commandPOST /goform/SetSysTimeCfg
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tenda SetSysTimeCfg timeZone Parameter Buffer Overflow Attempt (CVE-2025-51085, CVE-2025-8160)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:21; content:"/goform/SetSysTimeCfg"; fast_pattern; http.request_body; content:"timeZone|3d|"; pcre:"/^[^&]{100,}(?:&|$)/R"; reference:cve,2025-51085; reference:url,github.com/TL-SN/IOT; reference:url,github.com/CH13hh/cve; reference:cve,2025-8160; classtype:web-application-attack; sid:2063754; rev:1; metadata:affected_product Tenda, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_07_25, cve CVE_2025_51085, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_07_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
timeZone=<100+ bytes>
  • Exploit is delivered via HTTP POST to /goform/SetSysTimeCfg; the timeZone parameter must be present in the request body with a value of 100 or more characters (no intervening '&') to trigger the buffer overflow.
  • The URI path has an exact byte size of 21; use bsize matching to reduce false positives.
  • Traffic is plaintext (no TLS); detection should be applied at perimeter and internal network boundaries.
  • Public exploit code is available; treat any matching traffic as high-confidence exploitation attempt.
  • PoC references are available at github.com/TL-SN/IOT and github.com/CH13hh/cve.
  • ·Affected versions are Tenda AC20 up to and including 16.03.08.12; verify firmware version before applying mitigations.
  • ·The Snort/Suricata rule (sid:2063754) also covers CVE-2025-51085 which shares the same endpoint; ensure both CVEs are tracked together when triaging alerts.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.