CVE-2025-11847: Null Pointer Dereference
A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11847?
CVE-2025-11847 is classified as a high severity vulnerability due to its potential to trigger a denial-of-service condition.
How do I fix CVE-2025-11847?
To fix CVE-2025-11847, users should update their Zyxel VMG3625-T50B firmware to version 5.50(ABPM.9.6)C1 or later, and Zyxel WX3100-T0 firmware to version 5.50(ABVL.4.8)C1 or later.
Who is affected by CVE-2025-11847?
CVE-2025-11847 affects users of the Zyxel VMG3625-T50B and Zyxel WX3100-T0 firmware versions up to 5.50(ABPM.9.6)C0 and 5.50(ABVL.4.8)C0, respectively.
What causes the vulnerability in CVE-2025-11847?
CVE-2025-11847 is caused by a null pointer dereference in the IP settings CGI program within the affected Zyxel firmware.
What type of attacks can exploit CVE-2025-11847?
CVE-2025-11847 can be exploited by an authenticated attacker with administrator privileges to cause a denial-of-service condition.