CVE-2025-38725
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may cre...
Affects 2 products across 4 vendors.
Software attempts to use a NULL pointer, causing a crash and denial of service.
The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could compromise availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.
BSID: BS-2026-GLOBAL-257000-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-38725?
What is the CVSS score for CVE-2025-38725?
Is CVE-2025-38725 actively exploited?
How do I remediate CVE-2025-38725?
What systems are affected by CVE-2025-38725?
What NERC-CIP standard applies to CVE-2025-38725?
What IEC 62443 requirement maps to CVE-2025-38725?
| CVE ID | CVE-2025-38725 |
|---|---|
| BSID | BS-2026-GLOBAL-257000-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Published | 2025-09-04 |
| Last Modified | 2026-07-14 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.
Source: NIST NVD / MITRE CVE Database
The vulnerabilities are locally exploitable with low privileges and do not require user interaction. An attacker with local access can potentially exploit these issues to cause a denial of service or execute arbitrary code.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Debian | Debian Linux | — |
| Fujitsu-Siemens | — | — |
| Linux | Linux Kernel | — |
| Siemens | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access controls and monitor for unusual activity on affected systems.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE could allow an attacker to compromise the availability of critical systems, which violates the requirement for maintaining the reliability of the bulk electric system.
The vulnerabilities could be exploited to affect the availability and integrity of the control system, which is a key requirement under IEC 62443-3-3 for secure system design and operation.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | cc940282cd5e45685757c8b77c6da7217b40d99b3503ac18480e7b77ffce50e8dd9c47dd76db6a045668ced195800ef73bed8083dce9d6ac72c575068b5ced14 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →