PT-2026-21642 · Zyxel · Zyxel Wx3100-T0+1

Published

2026-02-24

·

Updated

2026-02-24

·

CVE-2025-11848

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG3625-T50B versions prior to 5.50(ABPM.9.6)C0 Zyxel WX3100-T0 versions prior to 5.50(ABVL.4.8)C0
Description A flaw exists in the Wake-on-LAN CGI program that could allow an attacker with administrator privileges to cause a denial-of-service (DoS) condition. This is triggered by sending a specially crafted HTTP request. The issue involves a null pointer dereference.
Recommendations Update Zyxel VMG3625-T50B to version 5.50(ABPM.9.6)C0 or later. Update Zyxel WX3100-T0 to version 5.50(ABVL.4.8)C0 or later.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11848

Affected Products

Zyxel Vmg3625-T50B
Zyxel Wx3100-T0