CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerability
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Other sources
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11667?
CVE-2024-11667 has been classified with a high severity due to its potential to allow unauthorized access through directory traversal.
How do I fix CVE-2024-11667?
To fix CVE-2024-11667, update your Zyxel ATP or USG FLEX series device firmware to versions above 5.38.
Which products are affected by CVE-2024-11667?
CVE-2024-11667 affects various Zyxel ATP series and USG FLEX series firmware versions from V5.00 to V5.38.
What could an attacker achieve by exploiting CVE-2024-11667?
By exploiting CVE-2024-11667, an attacker could gain unauthorized access to the web management interface and manipulate server files.
Is CVE-2024-11667 still a threat to my device if updated?
No, updating to the latest firmware mitigates the risk associated with CVE-2024-11667.