PT-2025-41759 · D Link · D-Link Dap-2695

Iot_Res

·

Published

2025-10-11

·

Updated

2025-11-03

·

CVE-2025-11665

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP-2695 version 2.00RC131
Description A flaw exists in the D-Link DAP-2695 related to the Firmware Update Handler component. Specifically, the fwupdater main function within the rgbin file is susceptible to os command injection. This issue can be triggered remotely through manipulation. The maintainer no longer supports the affected product.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-13176
CVE-2025-11665

Affected Products

D-Link Dap-2695