CVE-2025-4859
A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue affects some unknown processing of the file /adv_macbypass.php of the component MAC Bypass Settings Page. The manipulation of the argument f_mac leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. This vulnerability only affects products that are no longer supported by the maintainer.
Published:May 18, 2025
Last Modified:May 22, 2025
EPS:May 18, 2025
EPSS Score:0.00049
CVSS Score:2.4
Affected Products
Vendor
Product
Action
Vendor
Dlink
Product
Dap-2695
Dlink
Dap-2695
Vendor
Dlink
Product
Dap-2695 Firmware
Dlink
Dap-2695 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
