VendorsD-Linkdap-2695any version
Vulnerabilities

D-Link DAP-2695 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2016-1558
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, and DAP-3662 1.01 and earlier allows remote attackers to have unspecified impact via a crafted 'dlink_uid' cookie.
Published 2017-04-21 · Modified
10.0EPSS 0.091
CVE-2025-12296
D-Link DAP-2695 Firmware Update sub_4174B0 os command injection
Published 2025-10-27 · Analyzed
9.8EPSS 0.070
CVE-2025-11665
D-Link DAP-2695 Firmware Update rgbin fwupdater_main os command injection
Published 2025-10-13 · Analyzed
9.8EPSS 0.068
CVE-2025-12295
D-Link DAP-2695 Firmware Update sub_40C6B8 signature verification
Published 2025-10-27 · Analyzed
8.1EPSS 0.004
CVE-2021-28840
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Published 2021-08-10 · Modified
7.5EPSS 0.023
CVE-2021-28838
Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.
Published 2021-08-10 · Modified
7.5EPSS 0.022
CVE-2021-28839
Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Published 2021-08-10 · Modified
7.5EPSS 0.014
CVE-2022-38873
D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta and earlier, DAP-3662 v1.05rc047 and earlier allows attackers to cause a Denial of Service (DoS) via uploading a crafted firmware after modifying the firmware header.
Published 2022-12-20 · Modified
7.5EPSS 0.005
CVE-2025-4859
D-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scripting
Published 2025-05-18 · Analyzed
4.8EPSS 0.009
CVE-2025-4858
D-Link DAP-2695 ARP Spoofing Prevention Page adv_arpspoofing.php cross site scripting
Published 2025-05-18 · Analyzed
4.8EPSS 0.008
CVE-2025-4860
D-Link DAP-2695 Static Pool Settings Page adv_dhcps.php cross site scripting
Published 2025-05-18 · Analyzed
4.8EPSS 0.008