PT-2026-21621 · Zyxel · Zyxel Wx3100-T0+1

Published

2026-02-24

·

Updated

2026-02-24

·

CVE-2025-11845

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0
Description A flaw exists in the certificate downloader CGI program that could allow a denial-of-service (DoS) condition. An authenticated attacker with administrator privileges can trigger this by sending a specially crafted HTTP request. The issue is due to a null pointer dereference.
Recommendations Update Zyxel VMG3625-T50B firmware to a version later than 5.50(ABPM.9.6)C0. Update Zyxel WX3100-T0 firmware to a version later than 5.50(ABVL.4.8)C0.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-11845

Affected Products

Zyxel Vmg3625-T50B
Zyxel Wx3100-T0