CVE-2025-11848

Published Feb 24, 2026

Last updated 3 months ago

Overview

Description
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
Source
security@zyxel.com.tw
NVD status
Analyzed
Products
ee5301-00_firmware, ee3301-00_firmware, dx5401-b1_firmware, dx4510-b1_firmware, dx4510-b0_firmware, dx3301-t0_firmware, dx3300-t1_firmware, dx3300-t0_firmware, ee6510-10_firmware, emg3525-t50b_firmware, emg5523-t50b_firmware, ex2210-t0_firmware, ex3300-t0_firmware, ex3300-t1_firmware, ex3301-t0_firmware, ex3500-t0_firmware, ex3501-t0_firmware, ex3510-b0_firmware, ex3510-b1_firmware, ex3600-t0_firmware, ex5401-b1_firmware, ex5510-b0_firmware, ex5512-t0_firmware, ex5601-t0_firmware, ex5601-t1_firmware, ex7501-b0_firmware, ex7710-b0_firmware, gm4100-b0_firmware, pm7500-00_firmware, vmg3625-t50b_firmware, vmg4005-b50a_firmware, vmg4005-b60a_firmware, ax7501-b1_firmware, pe3301-00_firmware, pe5301-01_firmware, pm3100-t0_firmware, pm5100-t0_firmware, pm5100-t1_firmware, pm7300-t0_firmware, px3321-t1_firmware, px5301-t0_firmware, scr_50axe_firmware, vmg8623-t50b_firmware, we3300-00_firmware, wx3100-t0_firmware, wx3401-b1_firmware, wx5600-t0_firmware, wx5610-b0_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
4.9
Impact score
3.6
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

security@zyxel.com.tw
CWE-476

Social media

Hype score
Not currently trending

Configurations