Junglewise Threat Intelligence

CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerability

CVE-2024-11667 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-03

Technologies: Zyxel Multiple Firewalls, Zyxel Firewalls. Vendors: Zyxel.

Executive brief

A directory traversal vulnerability in the web management interface of multiple Zyxel firewall series allows a remote attacker to download or upload files via a crafted URL. The flaw affects ATP, USG FLEX, and USG20(W)-VPN series running specific firmware versions between V5.00 and V5.38.

Affected products

  • Zyxel ATP series firmware V5.00 through V5.38
  • Zyxel USG FLEX series firmware V5.00 through V5.38
  • Zyxel USG FLEX 50(W) series firmware V5.10 through V5.38
  • Zyxel USG20(W)-VPN series firmware V5.10 through V5.38

Timeline

  • 2024-11-27: disclosed: Initial advisory by Zyxel Corporation
  • 2024-11-27: other: NVD Published Date
  • 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-03: advisory: CISA advisory published

Related threats