D-Link DAP-2695 Firmware Signature Verification Vulnerability

Vulnerability

A vulnerability exists in the D-Link DAP-2695 access point running firmware version 2.00RC13. The issue arises in the Firmware Update Handler, specifically in the function sub_40C6B8, where there is improper verification of cryptographic signatures during the firmware update process. This vulnerability allows remote attackers to bypass integrity checks by manipulating the magic number and exploiting the use of the weak MD5 hashing algorithm. As a result, unauthorized firmware updates could be applied, potentially leading to further exploitation.

Impact

Exploitation of this vulnerability allows for unauthorized firmware updates by bypassing cryptographic signature verification. This could lead to the installation of malicious firmware, with the potential for further exploitation of the device.

Added: Oct 27, 2025, 5:35 PM
Updated: Oct 27, 2025, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.