CVE-2024-11667

Confirmed PUBLISHED

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series...

Zyxel · ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware
Exploited in the wild Used in malware

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High

At a Glance

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

edge ransomware malware cisa
CVE Published
Nov 27, 2024
Exploitation Reported
Dec 03, 2024
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
zyxel
usg_flex_firmware

5.00 to <= 5.38

Affected
zyxel
atp_firmware

5.00 to <= 5.38

Affected
zyxel
usg20-vpn_firmware

5.10 to <= 5.38

Affected
zyxel
usg_flex_50w_firmware

5.10 to < 5.38

Affected
Zyxel
ATP series firmware

versions V5.00 through V5.38

Affected
Zyxel
USG FLEX series firmware

versions V5.00 through V5.38

Affected
Zyxel
USG FLEX 50(W) series firmware

versions V5.10 through V5.38

Affected
Zyxel
USG20(W)-VPN series firmware

versions V5.10 through V5.38

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.