peter bassill · operator
$ cve CVE-2024-11667 JSON

CVE-2024-11667 KEV

7.5
HIGH · CVSS 3.1 · EPSS 2.9% (pctl 87)

Patch first

On CISA KEV — known exploited in the wild, due 2024-12-24.

Description

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS2.93% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2024-12-24
Public exploitnone known
Published2024-11-27
Last modified2026-08-05

CISA KEV

NameZyxel Multiple Firewalls Path Traversal Vulnerability
Added2024-12-03
Due2024-12-24
Vendor / productZyxel / Multiple Firewalls
Ransomware useknown

Affected (18)

VendorProduct
zyxelatp
zyxelatp100
zyxelatp100w
zyxelatp200
zyxelatp500
zyxelatp700
zyxelatp800
zyxelusg 20w-vpn
zyxelusg flex
zyxelusg flex 100
zyxelusg flex 100ax
zyxelusg flex 100w
zyxelusg flex 200
zyxelusg flex 50
zyxelusg flex 500
zyxelusg flex 50w
zyxelusg flex 700
zyxelzld

References

→ the Explorer  ·  watch your stack  ·  NVD