CVE-2025-38725

MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may cre...

Affects 2 products across 4 vendors.

BCS5.13
CVSS 3.15.5
EPSS0.1%
Percentile4th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-476: NULL Pointer Dereference

Software attempts to use a NULL pointer, causing a crash and denial of service.

◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could compromise availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.

BSID: BS-2026-GLOBAL-257000-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-38725?
The Siemens SIMATIC CN 4100 is affected by multiple vulnerabilities, including NULL Pointer Dereference, Reachable Assertion, Use After Free, and Out-of-bounds Write, which could compromise availability, integrity, and confidentiality. Siemens recommends updating to the latest version to mitigate these risks.
What is the CVSS score for CVE-2025-38725?
CVE-2025-38725 has CVSS 5.5 (Medium). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. EPSS: 0.1%.
Is CVE-2025-38725 actively exploited?
No confirmed active exploitation of CVE-2025-38725 as of 2026-07-15.
How do I remediate CVE-2025-38725?
Priority: MEDIUM. Advisory: https://git.kernel.org/stable/c/4faff70959d51078f9ee8372f8cff0d7045e4114
What systems are affected by CVE-2025-38725?
CVE-2025-38725 affects: Debian, Fujitsu-Siemens, Linux, Siemens.
What NERC-CIP standard applies to CVE-2025-38725?
NERC CIP CIP-007 CIP-007-R2: This CVE could allow an attacker to compromise the availability of critical systems, which violates the requirement for maintaining the reliability of the bulk electric system.
What IEC 62443 requirement maps to CVE-2025-38725?
IEC 62443 SR 7.6: The vulnerabilities could be exploited to affect the availability and integrity of the control system, which is a key requirement under IEC 62443-3-3 for secure system design and operation.
Vulnerability Details
CVE IDCVE-2025-38725
BSIDBS-2026-GLOBAL-257000-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Published2025-09-04
Last Modified2026-07-14
ICS Relevance65%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerabilities are locally exploitable with low privileges and do not require user interaction. An attacker with local access can potentially exploit these issues to cause a denial of service or execute arbitrary code.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Debian Debian Linux
Fujitsu-Siemens —
Linux Linux Kernel
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 313 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict access controls and monitor for unusual activity on affected systems.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE could allow an attacker to compromise the availability of critical systems, which violates the requirement for maintaining the reliability of the bulk electric system.
IEC 62443: SR 7.6
The vulnerabilities could be exploited to affect the availability and integrity of the control system, which is a key requirement under IEC 62443-3-3 for secure system design and operation.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashcc940282cd5e45685757c8b77c6da7217b40d99b3503ac18480e7b77ffce50e8dd9c47dd76db6a045668ced195800ef73bed8083dce9d6ac72c575068b5ced14
Related CVEs affecting Debian
CVE-2003-0098 10.0 Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allo... CVE-1999-0698 10.0 Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. CVE-2003-0648 10.0 Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local use... CVE-1999-0046 10.0 Buffer overflow of rlogin program using TERM environmental variable. CVE-2004-0964 10.0 Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux,...
View all Debian CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →