CVE-2025-11848: Null Pointer Dereference
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11848?
CVE-2025-11848 has been classified as a high severity vulnerability due to its potential to allow denial-of-service attacks.
How do I fix CVE-2025-11848?
To fix CVE-2025-11848, update the firmware of the Zyxel VMG3625-T50B or WX3100-T0 to the latest version beyond 5.50(ABPM.9.6)C0 and 5.50(ABVL.4.8)C0 respectively.
Who is affected by CVE-2025-11848?
CVE-2025-11848 affects Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0.
What type of vulnerability is CVE-2025-11848?
CVE-2025-11848 is a null pointer dereference vulnerability that can lead to denial-of-service.
Can CVE-2025-11848 be exploited remotely?
CVE-2025-11848 requires an authenticated attacker with administrator privileges to exploit the vulnerability.