Nihon Kohden earned ICSMA-25-296-01 for the CNS-6201 central monitor, software 01-03 through 01-06. CVE-2025-59668, a null-pointer dereference, base score 7.5. A remote attacker triggers a denial of service on the central station, which is the nurses-station screen aggregating vitals from every bed it watches. Take it down and you have not hurt one patient, you have blinded a unit.

A null-pointer dereference is among the most ordinary ways software falls over: the program takes in input it does not fully check, follows a path that assumes a value is present, reaches for a pointer that is not, and collapses. The pattern keeps surfacing in bedside and central monitoring gear because the input handling was written for well-formed messages from trusted peers on a closed clinical network, and that closed network is a comforting fiction.

The clinical weight sits in what the central station does. It is the panel that gathers the vital-sign feeds from across a ward into a shared field of view, and when it drops, the trend lines and threshold alarms for every bed on it go dark at once. Staff fall back to checking patients in person, room by room, slower and blind to the gradual drift a monitor is meant to catch. The harm is not lost records but lost situational awareness across a whole unit.

Concentrating many patients onto a shared aggregation point buys efficiency and creates a place worth attacking. A remote input that reliably crashes it turns a low-glamour defect into something that can degrade care for everyone downstream. Monitoring infrastructure has tended to be treated as passive plumbing, judged on uptime rather than adversarial resilience, and findings like this are why that framing has been shifting.

Jared Quinn of QuinnTech.ai reported it. Nihon Kohden publishes an advisory archive going back years, which is more than most of its peers can say. Availability is a safety property here, not an IT metric. A monitor that crashes is a monitor that is not monitoring.