CVE-2024-11667
high · 7.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Added 2024-12-03Remediation due 2024-12-24
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
7.5
CVSS
2.9%
EPSS (exploit prob.)
86th
EPSS percentile
2024-11-27
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zyxel | zld | >= 5.00, <= 5.38 |
| zyxel | atp | all versions |
| zyxel | atp100 | all versions |
| zyxel | atp100w | all versions |
| zyxel | atp200 | all versions |
| zyxel | atp500 | all versions |
| zyxel | atp700 | all versions |
| zyxel | atp800 | all versions |
| zyxel | zld | >= 5.00, <= 5.38 |
| zyxel | usg_flex | all versions |
| zyxel | usg_flex_100 | all versions |
| zyxel | usg_flex_100ax | all versions |
| zyxel | usg_flex_100w | all versions |
| zyxel | usg_flex_200 | all versions |
| zyxel | usg_flex_50 | all versions |
| zyxel | usg_flex_500 | all versions |
| zyxel | usg_flex_700 | all versions |
| zyxel | zld | >= 5.10, <= 5.38 |
| zyxel | usg_flex_50w | all versions |
| zyxel | zld | >= 5.10, <= 5.38 |
| zyxel | usg_20w-vpn | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-11667