CVE-2025-11665: D-Link Dap-2695 Firmware

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

  • D-Link Dap-2695 Firmware: version 2.00 only

Published 2025-10-13. Last modified 2026-10-08.