Command Injection Vulnerability in D-Link DAP-2695 Firmware Update Component
CVE-2025-11665
5.1MEDIUM
What is CVE-2025-11665?
A security flaw in the firmware update handler of the D-Link DAP-2695 allows remote attackers to execute arbitrary OS commands. This is due to improper neutralization of argument delimiters in the command processing code. Specifically, the vulnerability resides in the fwupdater_main function within the rgbin file, enabling potential exploitation on unsupported products. Users are encouraged to cease using or update their firmware to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DAP-2695 2.00RC131
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
IOT_Res (VulDB User)