CVE-2025-11846: Null Pointer Dereference
A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11846?
CVE-2025-11846 has a high severity rating as it allows authenticated attackers with administrator privileges to trigger a denial of service.
How do I fix CVE-2025-11846?
To fix CVE-2025-11846, update to the latest firmware version provided by Zyxel that addresses this vulnerability.
What products are affected by CVE-2025-11846?
CVE-2025-11846 affects several Zyxel products including the VMG3625-T50B and WX3100-T0 firmware versions up to specified versions.
Who can exploit CVE-2025-11846?
Only authenticated users with administrator privileges can exploit the vulnerability described in CVE-2025-11846.
What type of vulnerability is CVE-2025-11846?
CVE-2025-11846 is classified as a null pointer dereference vulnerability.