← Vulnerability feed

Vulnerability record · CVE-2024-11667 · published 27 November 2024

CVE-2024-11667: Zyxel Firewall Web Management Path Traversal Allows File Upload and Download

Zyxel · Zld

A path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an attacker craft a URL to read or write files on the device. Because the interface is network-reachable and the flaw requires no credentials, it exposes firewall appliances that are often internet-facing. CISA added it to KEV with known ransomware campaign use, so it is being exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 3 Dec 2024 Known ransomware use EPSS 2.9% · top 13.5% CWE-22 · Path traversal
9.8CVSS 3.1 base score
2.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
5 Aug 2026Last modified by NVD

Description

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, active exploitation in CISA KEV, and documented ransomware use make this an urgent edge-device risk.

What it is

A path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an attacker craft a URL to read or write files on the device. Because the interface is network-reachable and the flaw requires no credentials, it exposes firewall appliances that are often internet-facing. CISA added it to KEV with known ransomware campaign use, so it is being exploited in the wild.

Impact

An unauthenticated attacker can download sensitive files from the device and upload arbitrary files, which can lead to credential theft, configuration tampering, or code execution on the firewall. Compromise of the firewall gives a foothold at the network edge.

Attack surface

Reached over the network through the web management interface via a crafted URL; the CVSS vector shows no privileges and no user interaction required. Any exposed management interface is a candidate target.

Exploitation

CISA KEV lists it as exploited and associated with known ransomware campaigns, with a remediation due date of 2024-12-24. EPSS 30-day probability is about 2.9 percent (86th percentile), so exploitation is targeted rather than mass-scanning.

What to do

  • Apply the vendor firmware update from the Zyxel security advisory for the affected ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN firmware versions.
  • If patching is not immediately possible, disable or restrict access to the web management interface from untrusted networks per vendor guidance.
  • Place management interfaces behind a VPN or allowlist of trusted administrative IPs; do not expose them directly to the internet.
  • Rotate credentials and review device configuration for unauthorized changes after any suspected exposure.
  • Monitor CISA KEV guidance and vendor advisory for updated mitigation instructions.

Detection

  • Review web management logs for URL requests containing traversal sequences such as ../ or encoded variants against the firewall interface.
  • Alert on unexpected file upload or download activity through the management interface, especially from untrusted source IPs.
  • Hunt for new or modified files on the firewall filesystem and for anomalous outbound connections from the device.
  • Correlate firewall management access logs with authentication events to spot unauthenticated access attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-11667 to the Known Exploited Vulnerabilities catalog on 3 December 2024 as "Zyxel Multiple Firewalls Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-11667 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-25014Zyxel zld out-of-bounds write vulnerabilityA stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows r…EPSS 4.4%8.1CVE-2025-9133Zyxel zld missing authorization vulnerabilityA missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th…EPSS 5.5%8.1CVE-2024-42057Zyxel zld os command injection vulnerabilityA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v…EPSS 1.3%7.5CVE-2024-42058Zyxel zld null pointer dereference vulnerabilityA null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50…EPSS 0.62%7.5CVE-2023-4398Zyxel zld integer overflow vulnerabilityAn integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions …EPSS 0.88%7.2CVE-2025-8078Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…EPSS 1.4%7.2CVE-2024-7203Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver…EPSS 1.3%7.2CVE-2024-42059Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-11667), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.