Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA reports that CVE‑2024‑11667, a path‑traversal flaw in the Zyxel firewall web interface, is already being exploited in the wild.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA lists CVE-2024-11667 as a KEV due to ransomware exploitation, with a path traversal flaw that lets attackers download or upload files via crafted URLs; no PoC or patch details are provided.
PatchDay Alert[verified]@patchdayalertDisclosure
Zyxel issued a patch for CVE‑2024‑11667 before customers were alerted, illustrating a disclosure failure where the exploitation existed but the warning arrived too late.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The linked research indicates that CVE‑2024‑11667 is actively exploited against multiple firewalls, yet it provides no patch, exploit code details, or in‑depth technical analysis.