ZeroHour

CVE-2024-11667

KEV ransomwarelarge

Unauthenticated Path Traversal in Zyxel ATP, USG FLEX, and USG20-VPN Firewalls

CISA: Zyxel Multiple Firewalls Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2024-11667 is a directory traversal vulnerability (CWE-22) in the web management interface of several Zyxel firewall lines, allowing an unauthenticated remote attacker to download or upload files via a crafted URL. It is triggered over the network with no privileges or user interaction required, earning a critical CVSS 3.1 score of 9.8. Successful exploitation can expose sensitive files on the device and support broader intrusions, and CISA notes the flaw is being used in ransomware campaigns. Organizations running Zyxel ATP or USG FLEX firewalls on firmware V5.00–V5.38, or USG FLEX 50(W)/USG20(W)-VPN firewalls on V5.10–V5.38, are affected, particularly where the management interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-03 with known ransomware use; no public proof-of-concept is known.

What to do: Upgrade affected ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN firewalls to a fixed firmware release per Zyxel's security advisory (any version above the affected V5.00–V5.38 / V5.10–V5.38 ranges); per CISA's KEV required action, apply the vendor's mitigations or discontinue use if mitigations are unavailable. Until patched, restrict or disable WAN-side HTTP/HTTPS management access to these devices and prioritize internet-exposed units. Given known ransomware use, hunt for signs of compromise on exposed devices, including unexpected uploaded files or anomalous administrative traffic.

Affected
Zyxel ATP series firewallsV5.00 through V5.38
Zyxel USG FLEX series firewallsV5.00 through V5.38
Zyxel USG FLEX 50(W) series firewallsV5.10 through V5.38
Zyxel USG20(W)-VPN series firewallsV5.10 through V5.38
Estimated exposure
largeon the order of tens of thousands of internet-exposed firewalls (10k–100k range; total installed base plausibly in the hundreds of thousands) — estimate — Zyxel's ATP and USG FLEX series are widely deployed SMB/mid-market security gateways, and public internet-wide scans typically index tens of thousands of Zyxel firewall management interfaces exposed online, with the broader installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

CISA Known Exploited Vulnerability
Affected
Zyxel Multiple Firewalls
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
zyxel
Products
zld
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news