CVE-2024-11667
KEV ransomwarelargeUnauthenticated Path Traversal in Zyxel ATP, USG FLEX, and USG20-VPN Firewalls
CISA: Zyxel Multiple Firewalls Path Traversal Vulnerability
CVE-2024-11667 is a directory traversal vulnerability (CWE-22) in the web management interface of several Zyxel firewall lines, allowing an unauthenticated remote attacker to download or upload files via a crafted URL. It is triggered over the network with no privileges or user interaction required, earning a critical CVSS 3.1 score of 9.8. Successful exploitation can expose sensitive files on the device and support broader intrusions, and CISA notes the flaw is being used in ransomware campaigns. Organizations running Zyxel ATP or USG FLEX firewalls on firmware V5.00–V5.38, or USG FLEX 50(W)/USG20(W)-VPN firewalls on V5.10–V5.38, are affected, particularly where the management interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-03 with known ransomware use; no public proof-of-concept is known.
What to do: Upgrade affected ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN firewalls to a fixed firmware release per Zyxel's security advisory (any version above the affected V5.00–V5.38 / V5.10–V5.38 ranges); per CISA's KEV required action, apply the vendor's mitigations or discontinue use if mitigations are unavailable. Until patched, restrict or disable WAN-side HTTP/HTTPS management access to these devices and prioritize internet-exposed units. Given known ransomware use, hunt for signs of compromise on exposed devices, including unexpected uploaded files or anomalous administrative traffic.
| Zyxel ATP series firewalls | V5.00 through V5.38 |
| Zyxel USG FLEX series firewalls | V5.00 through V5.38 |
| Zyxel USG FLEX 50(W) series firewalls | V5.10 through V5.38 |
| Zyxel USG20(W)-VPN series firewalls | V5.10 through V5.38 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
- Affected
- Zyxel Multiple Firewalls
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- zyxel
- Products
- zld
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H