CVE-2025-11848
Received Received - Intake
Null Pointer Dereference in Zyxel Wake-on-LAN Causes DoS

Publication date: 2026-02-24

Last updated on: 2026-02-25

Assigner: Zyxel Corporation

Description
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-24
Last Modified
2026-02-25
Generated
2026-06-16
AI Q&A
2026-02-24
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 49 associated CPEs
Vendor Product Version / Range
zyxel ee5301-00_firmware to 5.63(acld.2.1 (exc)
zyxel ee3301-00_firmware to 5.63(acmu.2.1 (exc)
zyxel dx5401-b1_firmware to 5.17(abyo.7.1 (exc)
zyxel dx4510-b1_firmware to 5.17(abyl.10.1 (exc)
zyxel dx4510-b0_firmware to 5.17(abyl.10.1 (exc)
zyxel dx3301-t0_firmware to 5.50(abvy.7.1 (exc)
zyxel dx3300-t1_firmware to 5.50(abvy.7.1 (exc)
zyxel dx3300-t0_firmware to 5.50(abvy.7.1 (exc)
zyxel ee6510-10_firmware to 5.19(acjq.4.1 (exc)
zyxel emg3525-t50b_firmware to 5.50(abpm.9.7 (exc)
zyxel emg5523-t50b_firmware to 5.50(abpm.9.7 (exc)
zyxel ex2210-t0_firmware to 5.50(acdi.2.3 (exc)
zyxel ex3300-t0_firmware to 5.50(abvy.7.1 (exc)
zyxel ex3300-t1_firmware to 5.50(abvy.7.1 (exc)
zyxel ex3301-t0_firmware to 5.50(abvy.7.1 (exc)
zyxel ex3500-t0_firmware to 5.44(achr.5.1 (exc)
zyxel ex3501-t0_firmware to 5.44(achr.5.1 (exc)
zyxel ex3510-b0_firmware to 5.17(abup.15.2 (exc)
zyxel ex3510-b1_firmware to 5.17(abup.15.2 (exc)
zyxel ex3600-t0_firmware to 5.70(acif.2.1 (exc)
zyxel ex5401-b1_firmware to 5.17(abyo.7.1 (exc)
zyxel ex5510-b0_firmware to 5.17(abqx.11.1 (exc)
zyxel ex5512-t0_firmware to 5.70(aceg.5.3 (exc)
zyxel ex5601-t0_firmware to 5.70(acdz.5.1 (exc)
zyxel ex5601-t1_firmware to 5.70(acdz.5.1 (exc)
zyxel ex7501-b0_firmware to 5.18(achn.3.1 (exc)
zyxel ex7710-b0_firmware to 5.18(acak.1.6 (exc)
zyxel gm4100-b0_firmware to 5.18(accl.2 (exc)
zyxel pm7500-00_firmware to 5.61(ackk.1.2 (exc)
zyxel vmg3625-t50b_firmware to 5.50(abpm.9.7 (exc)
zyxel vmg4005-b50a_firmware to 5.17(abqa.3.2 (exc)
zyxel vmg4005-b60a_firmware to 5.17(abqa.3.2 (exc)
zyxel ax7501-b1_firmware to 5.17(abpc.7.1 (exc)
zyxel pe3301-00_firmware to 5.63(acmt.2.1 (exc)
zyxel pe5301-01_firmware to 5.63(acoj.2.1 (exc)
zyxel pm3100-t0_firmware to 5.42(acbf.4.1 (exc)
zyxel pm5100-t0_firmware to 5.42(acbf.4.1 (exc)
zyxel pm5100-t1_firmware to 5.42(acbf.4.1 (exc)
zyxel pm7300-t0_firmware to 5.42(abyy.4.1 (exc)
zyxel px3321-t1_firmware to 5.44(achk.3 (exc)
zyxel px3321-t1_firmware to 5.44(acjb.1.5 (exc)
zyxel px5301-t0_firmware to 5.44(ackb.0.6 (exc)
zyxel scr_50axe_firmware to 1.30(acgn.0 (exc)
zyxel vmg8623-t50b_firmware to 5.50(abpm.9.7 (exc)
zyxel we3300-00_firmware to 5.70(acka.1.1 (exc)
zyxel wx3100-t0_firmware to 5.50(abvl.4.9 (exc)
zyxel wx3401-b1_firmware to 5.17(abve.2.10 (exc)
zyxel wx5600-t0_firmware to 5.70(aceb.5.1 (exc)
zyxel wx5610-b0_firmware to 5.18(acgj.0.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a null pointer dereference issue found in the Wake-on-LAN CGI program of certain Zyxel firmware versions (VMG3625-T50B and WX3100-T0). An authenticated attacker with administrator privileges can exploit this flaw by sending a specially crafted HTTP request, which causes the program to dereference a null pointer.

This results in a denial-of-service (DoS) condition, meaning the affected device or service could crash or become unresponsive.

Impact Analysis

The primary impact of this vulnerability is a denial-of-service (DoS) condition on the affected Zyxel devices. An attacker with administrator privileges can cause the device to crash or become unresponsive by sending a crafted HTTP request.

This could disrupt network availability or device functionality, potentially affecting network operations that rely on these devices.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11848. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart