← Vulnerability feed

Vulnerability record · CVE-2025-12295 · published 27 October 2025

CVE-2025-12295: Dlink dap-2695 firmware insufficient verification of data authenticity vulnerability

Dlink · Dap 2695 Firmware

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

6.6 CVSS 4.0 Medium EPSS 0.41% · top 67.2% CWE-345 · Insufficient verification of data authenticityCWE-347 · Improper verification of cryptographic signature
6.6CVSS 4.0 base score, v2 6.8
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Dlink/DAP-2695_Inte.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.329963 Permissions RequiredVDB Entry
https://vuldb.com/?id.329963 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.675854 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product

Track CVE-2025-12295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-1558Dlink dap-3662 firmware memory buffer overflow vulnerabilityBuffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP…EPSS 9.1%7.5CVE-2022-38873Dlink dap-2310 firmware insufficient verification of data authenticity vulnerabilityD-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DA…EPSS 0.48%7.5CVE-2021-28838Dlink dap-2310 firmware null pointer dereference vulnerabilityNull pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1…EPSS 2.2%7.5CVE-2021-28839Dlink dap-2310 firmware null pointer dereference vulnerabilityNull Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 …EPSS 1.4%7.5CVE-2021-28840Dlink dap-2310 firmware null pointer dereference vulnerabilityNull Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 …EPSS 2.3%5.1CVE-2025-11665Dlink dap-2695 firmware command injection vulnerabilityA vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Updat…EPSS 6.8%4.8CVE-2025-4860Dlink dap-2695 firmware cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137_ALL_en_20210528. Affected is an unknown function of the file /…EPSS 0.81%4.8CVE-2025-4859Dlink dap-2695 firmware cross-site scripting vulnerabilityA vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue affects some unknown processing…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2025-12295), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.