cvedb.io
CVE-2024-11667
HIGH · CVSS 7.5 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 86%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2024-12-03 · Last modified 2026-08-05T05:16:40.797

Summary

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

Affected products

Zyxel — Multiple Firewalls

Does this affect you?

Add your gear to cvedb and we'll alert you only when Zyxel ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.