Vulnerability Description
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Ex5601-T1 Firmware | < 5.70\(acdz.5.1\)c0 |
| Zyxel | Ex5601-T1 | - |
| Zyxel | Ex7501-B0 Firmware | < 5.18\(achn.3.1\)c0 |
| Zyxel | Ex7501-B0 | - |
| Zyxel | Ex7710-B0 Firmware | < 5.18\(acak.1.6\)c0 |
| Zyxel | Ex7710-B0 | - |
| Zyxel | Gm4100-B0 Firmware | < 5.18\(accl.2\)c0 |
| Zyxel | Gm4100-B0 | - |
| Zyxel | Pm7500-00 Firmware | < 5.61\(ackk.1.2\)c0 |
| Zyxel | Pm7500-00 | - |
| Zyxel | Vmg3625-T50B Firmware | < 5.50\(abpm.9.7\)c0 |
| Zyxel | Vmg3625-T50B | - |
| Zyxel | Vmg4005-B50A Firmware | < 5.17\(abqa.3.2\)c0 |
| Zyxel | Vmg4005-B50A | - |
| Zyxel | Vmg4005-B60A Firmware | < 5.17\(abqa.3.2\)c0 |
| Zyxel | Vmg4005-B60A | - |
| Zyxel | Ax7501-B1 Firmware | < 5.17\(abpc.7.1\)c0 |
| Zyxel | Ax7501-B1 | - |
| Zyxel | Pe3301-00 Firmware | < 5.63\(acmt.2.1\)c0 |
| Zyxel | Pe3301-00 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-11848?
CVE-2025-11848 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL....
How severe is CVE-2025-11848?
CVE-2025-11848 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11848?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Ex5601-T1 Firmware, Zyxel Ex5601-T1, Zyxel Ex7501-B0 Firmware, Zyxel Ex7501-B0, Zyxel Ex7710-B0 Firmware.