A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
History
                    21 Oct 2025, 23:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
21 Oct 2025, 20:19
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
21 Oct 2025, 19:20
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
05 Dec 2024, 18:41
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100ax:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:* | |
| References | () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024 - Vendor Advisory | |
| First Time | Zyxel atp700 Zyxel atp Zyxel atp200 Zyxel usg Flex 100 Zyxel usg Flex 500 Zyxel usg 20w-vpn Zyxel usg Flex 50 Zyxel usg Flex Zyxel atp800 Zyxel usg Flex 50w Zyxel zld Zyxel usg Flex 700 Zyxel atp100w Zyxel atp100 Zyxel usg Flex 100ax Zyxel usg Flex 200 Zyxel Zyxel usg Flex 100w Zyxel atp500 | 
Information
                Published : 2024-11-27 10:15
Updated : 2025-10-21 23:16
NVD link : CVE-2024-11667
Mitre link : CVE-2024-11667
CVE.ORG link : CVE-2024-11667
JSON object : View
Products Affected
                zyxel
- atp
- usg_20w-vpn
- atp200
- atp500
- atp100w
- atp800
- usg_flex_50
- usg_flex_500
- atp100
- usg_flex_700
- usg_flex_50w
- usg_flex_100ax
- usg_flex_100
- zld
- usg_flex_100w
- usg_flex_200
- atp700
- usg_flex
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
