Vulnerability record · CVE-2024-11667 · published 27 November 2024
CVE-2024-11667: Zyxel Firewall Web Management Path Traversal Allows File Upload and Download
Zyxel · Zld
A path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an attacker craft a URL to read or write files on the device. Because the interface is network-reachable and the flaw requires no credentials, it exposes firewall appliances that are often internet-facing. CISA added it to KEV with known ransomware campaign use, so it is being exploited in the wild.
Description
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, active exploitation in CISA KEV, and documented ransomware use make this an urgent edge-device risk.
What it is
A path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an attacker craft a URL to read or write files on the device. Because the interface is network-reachable and the flaw requires no credentials, it exposes firewall appliances that are often internet-facing. CISA added it to KEV with known ransomware campaign use, so it is being exploited in the wild.
Impact
An unauthenticated attacker can download sensitive files from the device and upload arbitrary files, which can lead to credential theft, configuration tampering, or code execution on the firewall. Compromise of the firewall gives a foothold at the network edge.
Attack surface
Reached over the network through the web management interface via a crafted URL; the CVSS vector shows no privileges and no user interaction required. Any exposed management interface is a candidate target.
Exploitation
CISA KEV lists it as exploited and associated with known ransomware campaigns, with a remediation due date of 2024-12-24. EPSS 30-day probability is about 2.9 percent (86th percentile), so exploitation is targeted rather than mass-scanning.
What to do
- Apply the vendor firmware update from the Zyxel security advisory for the affected ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN firmware versions.
- If patching is not immediately possible, disable or restrict access to the web management interface from untrusted networks per vendor guidance.
- Place management interfaces behind a VPN or allowlist of trusted administrative IPs; do not expose them directly to the internet.
- Rotate credentials and review device configuration for unauthorized changes after any suspected exposure.
- Monitor CISA KEV guidance and vendor advisory for updated mitigation instructions.
Detection
- Review web management logs for URL requests containing traversal sequences such as ../ or encoded variants against the firewall interface.
- Alert on unexpected file upload or download activity through the management interface, especially from untrusted source IPs.
- Hunt for new or modified files on the firewall filesystem and for anomalous outbound connections from the device.
- Correlate firewall management access logs with authentication events to spot unauthenticated access attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-11667 to the Known Exploited Vulnerabilities catalog on 3 December 2024 as "Zyxel Multiple Firewalls Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-11667 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-11667), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.