CVE-2025-12295

CWE-345CWE-3473 documents3 sources
Severity
6.6MEDIUM
EPSS
0.2%
top 52.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27

Description

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer suppo

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/dap-26952.00RC13

🔴Vulnerability Details

2
GHSA
GHSA-fmw9-c6hw-79vg: A weakness has been identified in D-Link DAP-2695 22025-10-27
CVEList
D-Link DAP-2695 Firmware Update sub_40C6B8 signature verification2025-10-27
CVE-2025-12295 (MEDIUM CVSS 6.6) | A weakness has been identified in D | cvebase.io