CVE-2025-52222

D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:di-8100_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dlink:di-8100g_firmware:17.12.20a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8100g:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dlink:di-8004w_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8004w:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dlink:di-8003g_firmware:17.12.21a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8003g:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dlink:di-8500_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8500:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dlink:di-8200g_firmware:17.12.20a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8200g:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dlink:di-8200_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8200:a1:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*

History

14 Apr 2026, 15:45

Type Values Removed Values Added
CPE cpe:2.3:h:dlink:di-8100g:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8003g_firmware:17.12.21a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8200g_firmware:17.12.20a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8004w_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8200g:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8200:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8003g:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8200_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8100_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8100g_firmware:17.12.20a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-8500_firmware:16.07.26a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8004w:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-8500:-:*:*:*:*:*:*:*
First Time Dlink di-8003g Firmware
Dlink di-8200g Firmware
Dlink di-8200
Dlink di-8200 Firmware
Dlink di-8500 Firmware
Dlink di-8200g
Dlink di-8400
Dlink di-8100 Firmware
Dlink di-8003 Firmware
Dlink
Dlink di-8100g Firmware
Dlink di-8500
Dlink di-8004w Firmware
Dlink di-8004w
Dlink di-8100g
Dlink di-8100
Dlink di-8003g
Dlink di-8400 Firmware
Dlink di-8003
References () https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md - () https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md - Third Party Advisory
References () https://www.dlink.com/en/security-bulletin/ - () https://www.dlink.com/en/security-bulletin/ - Vendor Advisory

10 Apr 2026, 16:16

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

08 Apr 2026, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 18:24

Updated : 2026-04-14 15:45


NVD link : CVE-2025-52222

Mitre link : CVE-2025-52222

CVE.ORG link : CVE-2025-52222


JSON object : View

Products Affected

dlink

  • di-8003_firmware
  • di-8100g
  • di-8100_firmware
  • di-8200g_firmware
  • di-8003g
  • di-8200_firmware
  • di-8004w_firmware
  • di-8003g_firmware
  • di-8500_firmware
  • di-8200
  • di-8400_firmware
  • di-8100
  • di-8400
  • di-8200g
  • di-8003
  • di-8004w
  • di-8500
  • di-8100g_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')