Executive brief
Zyxel's ZLD firewall series (ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN models) contain a path traversal vulnerability in their CLI command for executing configuration files. An authenticated administrator could exploit this to execute malicious configuration files on affected devices, potentially compromising the firewall's integrity and the networks it protects. The vulnerability affects firmware versions from mid-2021 through early 2026.
Technical details
A path traversal vulnerability exists in the CLI command responsible for executing configuration files in Zyxel ZLD firewall firmware. The vulnerability allows an authenticated attacker with administrator privileges to craft a malicious configuration file and execute it on the affected device, likely by bypassing intended path restrictions. The attack requires network access to the device's management interface and valid administrator credentials. Patches are available as ZLD V5.43 for affected product lines, with earlier vulnerable versions spanning from V4.16 to V5.42 Patch 1 depending on the specific firewall model.
Affected products
- Zyxel ATP V4.32 to V5.42 Patch 1
- Zyxel USG FLEX V4.50 to V5.42 Patch 1
- Zyxel USG FLEX 50(W) V4.16 to V5.42 Patch 1
- Zyxel USG20(W)-VPN V4.16 to V5.42 Patch 1
Timeline
- 2026-08-04: disclosed