CVE-2025-4858: D-Link DAP-2695 ARP Spoofing Prevention Page adv_arpspoofing.php cross site scripting
A vulnerability was found in D-Link DAP-2695 120b36r137ALLen20210528. It has been declared as problematic. This vulnerability affects unknown code of the file /advarpspoofing.php of the component ARP Spoofing Prevention Page. The manipulation of the argument harpmac leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4858?
CVE-2025-4858 has been declared as problematic, indicating a significant vulnerability in the affected system.
How do I fix CVE-2025-4858?
To fix CVE-2025-4858, users should update their D-Link DAP-2695 device to the latest firmware version provided by D-Link.
What components are affected by CVE-2025-4858?
CVE-2025-4858 affects the ARP Spoofing Prevention Page of the D-Link DAP-2695.
What type of vulnerability is CVE-2025-4858?
CVE-2025-4858 is an argument manipulation vulnerability that can potentially lead to unauthorized access.
Which product is impacted by CVE-2025-4858?
CVE-2025-4858 specifically impacts the D-Link DAP-2695 device.