CVE-2025-4860: D-Link DAP-2695 Static Pool Settings Page adv_dhcps.php cross site scripting
A vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137ALLen20210528. Affected is an unknown function of the file /advdhcps.php of the component Static Pool Settings Page. The manipulation of the argument fmac leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4860?
CVE-2025-4860 is classified as a problematic vulnerability due to its potential to enable cross site scripting attacks.
How do I fix CVE-2025-4860?
To fix CVE-2025-4860, update the D-Link DAP-2695 firmware to the latest version provided by the vendor.
What component is affected by CVE-2025-4860?
CVE-2025-4860 affects the Static Pool Settings Page of the D-Link DAP-2695.
What type of vulnerability is CVE-2025-4860?
CVE-2025-4860 is a cross site scripting vulnerability that can be exploited through the manipulation of the f_mac argument.
Which product is impacted by CVE-2025-4860?
CVE-2025-4860 impacts the D-Link DAP-2695 wireless access point.