Vulnerability Description
A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Ex3510-B1 Firmware | < 5.17\(abup.15.2\)c0 |
| Zyxel | Ex3510-B1 | - |
| Zyxel | Ex3600-T0 Firmware | < 5.70\(acif.2.1\)c0 |
| Zyxel | Ex3600-T0 | - |
| Zyxel | Ex5401-B1 Firmware | < 5.17\(abyo.7.1\)c0 |
| Zyxel | Ex5401-B1 | - |
| Zyxel | Ex5510-B0 Firmware | < 5.17\(abqx.11.1\)c0 |
| Zyxel | Ex5510-B0 | - |
| Zyxel | Ex5512-T0 Firmware | < 5.70\(aceg.5.3\)c0 |
| Zyxel | Ex5512-T0 | - |
| Zyxel | Ex5601-T0 Firmware | < 5.70\(acdz.5.1\)c0 |
| Zyxel | Ex5601-T0 | - |
| Zyxel | Ex5601-T1 Firmware | < 5.70\(acdz.5.1\)c0 |
| Zyxel | Ex5601-T1 | - |
| Zyxel | Ex7501-B0 Firmware | < 5.18\(achn.3.1\)c0 |
| Zyxel | Ex7501-B0 | - |
| Zyxel | Ex7710-B0 Firmware | < 5.18\(acak.1.6\)c0 |
| Zyxel | Ex7710-B0 | - |
| Zyxel | Gm4100-B0 Firmware | < 5.18\(accl.2\)c0 |
| Zyxel | Gm4100-B0 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-11847?
CVE-2025-11847 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL...
How severe is CVE-2025-11847?
CVE-2025-11847 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11847?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Ex3510-B1 Firmware, Zyxel Ex3510-B1, Zyxel Ex3600-T0 Firmware, Zyxel Ex3600-T0, Zyxel Ex5401-B1 Firmware.