← Vulnerability feed

Vulnerability record · CVE-2024-42058 · published 3 September 2024

CVE-2024-42058: Zyxel zld null pointer dereference vulnerability

Zyxel · Zld

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from V5.20 through V5.38 could allow an unauthenticated attacker to cause DoS conditions by sending crafted packets to a vulnerable device.

7.5 CVSS 3.1 High EPSS 0.62% · top 52.4% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from V5.20 through V5.38 could allow an unauthenticated attacker to cause DoS conditions by sending crafted packets to a vulnerable device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-42058 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-11667Zyxel Firewall Web Management Path Traversal Allows File Upload and DownloadA path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an…KEVEPSS 2.9%analysed9.8CVE-2020-25014Zyxel zld out-of-bounds write vulnerabilityA stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows r…EPSS 4.4%8.1CVE-2025-9133Zyxel zld missing authorization vulnerabilityA missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th…EPSS 5.5%8.1CVE-2024-42057Zyxel zld os command injection vulnerabilityA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v…EPSS 1.3%7.5CVE-2023-4398Zyxel zld integer overflow vulnerabilityAn integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions …EPSS 0.88%7.2CVE-2025-8078Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…EPSS 1.4%7.2CVE-2024-7203Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver…EPSS 1.3%7.2CVE-2024-42059Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-42058), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.