AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-11848

MEDIUM · CVSS 4.9 EPSS 1.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.9. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2025-11848
Severity
MEDIUM
CVSS
4.9
EPSS
1.85%

Original NVD Description

A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)