CVE-2012-3816

WinRadius Server 2009 - Denial of Service via Long Password in Access-Request Packet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-3816. PoCs published by demonalex.

AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in WinRadius Server v2009 by sending a RADIUS authentication request with a password exceeding 240 characters, causing the server to crash. The PoC uses Perl with the Authen::Simple::RADIUS module to craft the malicious request.

Description

WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet.

Exploits (1)

exploitdb WORKING POC
by demonalex · textdoswindows
https://www.exploit-db.com/exploits/18945

This exploit demonstrates a Denial of Service (DoS) vulnerability in WinRadius Server v2009 by sending a RADIUS authentication request with a password exceeding 240 characters, causing the server to crash. The PoC uses Perl with the Authen::Simple::RADIUS module to craft the malicious request.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: WinRadius Server v2009
No auth needed
Prerequisites: Network access to the target WinRadius server · Perl with Authen::Simple::RADIUS module installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-05/0135.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53702
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49299
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18945
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75890

Scores

EPSS 0.0803
EPSS Percentile 94.0%

Details

Status published
Products (1)
winradius/winradius 2009
Published Jun 27, 2012
Tracked Since Feb 18, 2026