Executive brief
A directory traversal vulnerability in the web management interface of multiple Zyxel firewall series allows a remote attacker to download or upload files via a crafted URL. The flaw affects ATP, USG FLEX, and USG20(W)-VPN series running specific firmware versions between V5.00 and V5.38.
Affected products
- Zyxel ATP series firmware V5.00 through V5.38
- Zyxel USG FLEX series firmware V5.00 through V5.38
- Zyxel USG FLEX 50(W) series firmware V5.10 through V5.38
- Zyxel USG20(W)-VPN series firmware V5.10 through V5.38
Timeline
- 2024-11-27: disclosed: Initial advisory by Zyxel Corporation
- 2024-11-27: other: NVD Published Date
- 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-12-03: advisory: CISA advisory published