First published: Wed Nov 27 2024(Updated: )
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Credit: security@zyxel.com.tw security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Multiple Firewalls | ||
All of | ||
Zyxel ZLD Firmware | >=5.00<=5.38 | |
Any of | ||
Zyxel Advanced Threat Protection (ATP) | ||
Zyxel ATP100 Firmware | ||
Zyxel ATP100W Firmware | ||
Zyxel Zywall ATP200 | ||
Zyxel ATP500 Firmware | ||
Zyxel ATP700 Firmware | ||
Zyxel ATP series firmware | ||
All of | ||
Zyxel ZLD Firmware | >=5.00<=5.38 | |
Any of | ||
Zyxel USG FLEX | ||
Zyxel USG Flex 100 firmware | ||
Zyxel USG FLEX 100ax firmware | ||
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50w | ||
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX 700 firmware | ||
All of | ||
Zyxel ZLD Firmware | >=5.10<=5.38 | |
Zyxel USG FLEX 50(W) series firmware | ||
All of | ||
Zyxel ZLD Firmware | >=5.10<=5.38 | |
Zyxel USG20 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11667 has been classified with a high severity due to its potential to allow unauthorized access through directory traversal.
To fix CVE-2024-11667, update your Zyxel ATP or USG FLEX series device firmware to versions above 5.38.
CVE-2024-11667 affects various Zyxel ATP series and USG FLEX series firmware versions from V5.00 to V5.38.
By exploiting CVE-2024-11667, an attacker could gain unauthorized access to the web management interface and manipulate server files.
No, updating to the latest firmware mitigates the risk associated with CVE-2024-11667.