{"id": "CVE-2025-52222", "cveTags": [], "metrics": {"ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"id": "CVE-2025-52222", "role": "CISA Coordinator", "options": [{"exploitation": "none"}, {"automatable": "yes"}, {"technicalImpact": "partial"}], "version": "2.0.3", "timestamp": "2026-04-10T13:10:26.470216Z"}}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "affected": [{"source": "cve@mitre.org", "affectedData": [{"vendor": "n/a", "product": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}]}], "published": "2026-04-08T18:24:51.373", "references": [{"url": "https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.dlink.com/en/security-bulletin/", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "description": [{"lang": "en", "value": "CWE-120"}]}], "descriptions": [{"lang": "en", "value": "D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request."}, {"lang": "es", "value": "D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, y DI-8100G v17.12.20A1 fueron descubiertos por contener un desbordamiento de b\u00fafer a trav\u00e9s de los par\u00e1metros rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key y rd_ip en la funci\u00f3n radius_asp. Esta vulnerabilidad permite a los atacantes causar una denegaci\u00f3n de servicio (DoS) a trav\u00e9s de una solicitud manipulada."}], "lastModified": "2026-07-25T10:10:00.167", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8100_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FA39417-3894-4D6D-A899-000F56AA482B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8D417784-56F2-40AF-8FE8-C00E6F332131"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8100g_firmware:17.12.20a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A134EE00-C43F-41CC-9F7C-B94EA94E2113"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8100g:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DAA6037E-C080-4254-BDEC-1B5DFC64B937"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8004w_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E568896E-FDFE-4D97-B82E-5E983AE8AF45"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8004w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE1CEDFF-4310-444D-85F9-B93B77D0C73B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8003g_firmware:17.12.21a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FCE463D-0777-46D0-A102-81EB20622BA8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8003g:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "47C603E1-32FB-4335-B368-1E95529B3106"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA25536C-1B96-4611-BF35-A0AD24747929"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E6644787-50D7-4190-A2E3-DD54F43AE38C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8500_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47EBB0E8-37EF-4D2B-ADB3-1BDEC33829A3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "157BC421-0A70-4F55-840A-683A27F1BD5B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8200g_firmware:17.12.20a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "759CBE57-D426-4F76-BE51-BBB1276538A5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8200g:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D8F711B9-4D2E-4FE3-B1DB-68E3F15BCC26"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8200_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "694649F4-AF9D-456F-AC3E-3848B677013E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8200:a1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "95B5091D-76F9-49EC-8D21-A96549078BFB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7293D6F3-30C0-4805-A662-ADAC551BAB7A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "75CE4566-1587-4A8E-8D4E-8693149670DF"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}