CVE-2024-11667 KEV
7.5
HIGH · CVSS 3.1 · EPSS 2.9% (pctl 87)
Patch first
On CISA KEV — known exploited in the wild, due 2024-12-24.
Description
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 2.93% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2024-12-24 |
| Public exploit | none known |
| Published | 2024-11-27 |
| Last modified | 2026-08-05 |
CISA KEV
| Name | Zyxel Multiple Firewalls Path Traversal Vulnerability |
|---|---|
| Added | 2024-12-03 |
| Due | 2024-12-24 |
| Vendor / product | Zyxel / Multiple Firewalls |
| Ransomware use | known |
Affected (18)
| Vendor | Product |
|---|---|
| zyxel | atp |
| zyxel | atp100 |
| zyxel | atp100w |
| zyxel | atp200 |
| zyxel | atp500 |
| zyxel | atp700 |
| zyxel | atp800 |
| zyxel | usg 20w-vpn |
| zyxel | usg flex |
| zyxel | usg flex 100 |
| zyxel | usg flex 100ax |
| zyxel | usg flex 100w |
| zyxel | usg flex 200 |
| zyxel | usg flex 50 |
| zyxel | usg flex 500 |
| zyxel | usg flex 50w |
| zyxel | usg flex 700 |
| zyxel | zld |
References
→ the Explorer · watch your stack · NVD