---
id: CVE-2024-11667
title: "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware\_versions V5.00 through V5.38,\_USG FLEX 50(W) series firmware\_versions V5.10 through V…"
summary: "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware\_versions V5.00 through V5.38,\_USG FLEX 50(W) series firmware\_versions V5.10 through V…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: zyxel
product: zld
affected:
  - 'zld >= 5.00, <= 5.38'
  - 'zld >= 5.10, <= 5.38'
published: '2024-11-27'
updated: '2026-08-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-11667'
references:
  - url: >-
      https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024
    label: security@zyxel.com.tw
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11667
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.02929
epssPercentile: 0.86524
kev: true
kevDateAdded: '2024-12-03'
kevDueDate: '2024-12-24'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-05T11:47:23.454Z'
---

## Overview

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

## Affected

- `zld >= 5.00, <= 5.38`
- `zld >= 5.10, <= 5.38`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
