CVE-2025-11845: Null Pointer Dereference
A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11845?
CVE-2025-11845 is considered a high-severity vulnerability due to its potential to allow authenticated attackers to trigger a null pointer dereference.
How do I fix CVE-2025-11845?
To fix CVE-2025-11845, update the firmware of affected Zyxel devices to versions patched against this vulnerability.
Which devices are affected by CVE-2025-11845?
CVE-2025-11845 affects multiple Zyxel firmware versions across various products including VMG3625-T50B and WX3100-T0.
Who can exploit CVE-2025-11845?
Only authenticated users with administrator privileges can potentially exploit CVE-2025-11845.
What type of vulnerability is CVE-2025-11845?
CVE-2025-11845 is classified as a null pointer dereference vulnerability.