CVE-2026-14818: Path Traversal
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14818?
The severity of CVE-2026-14818 is high, rated at 7.2 on the CVSS scale.
How do I fix CVE-2026-14818?
To fix CVE-2026-14818, update the Zyxel firmware to the latest version that addresses this vulnerability.
What types of devices are affected by CVE-2026-14818?
CVE-2026-14818 affects Zyxel ATP series, USG FLEX series, and USG FLEX 50(W) series firmware versions specified.
What is a path traversal vulnerability as seen in CVE-2026-14818?
A path traversal vulnerability allows an attacker to access restricted files and directories on the server beyond the intended directory.
When was CVE-2026-14818 published?
CVE-2026-14818 was published on August 4, 2026.