CVE-2024-11667Active Exploitation(zyxel / atp)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch zyxel atp systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-24. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • atp
  • atp100
  • atp100w
  • atp200

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-02); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
atpatp100atp100watp200atp500atp700atp800usg_20w-vpnusg_flexusg_flex_100

1 version affected across 18 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-02: 3Mentions · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-02: 1Active Exploitation · 2026-05-02: 3Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-02: 205-0205-14
Signal classification2 categories
Active Exploitation
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-023
Active Exploitation3
2026-05-141
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-11667 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-12-03, signaling in-the-wild exploitation (CISA KEV entry) (CISA). The entry describes a path traversal in the Zyxel firewall web management interface that enables file…

    Post summary

    CISA reports that CVE‑2024‑11667, a path‑traversal flaw in the Zyxel firewall web interface, is already being exploited in the wild.

    1000038
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-11667: CISA adds CVE-2024-11667 to KEV: Zyxel firewall web UI path traversal allows file download/upload via crafted URLs; ransomware use flagged.

    Post summary

    CISA lists CVE-2024-11667 as a KEV due to ransomware exploitation, with a path traversal flaw that lets attackers download or upload files via crafted URLs; no PoC or patch details are provided.

    1000047
    152 followersView on X
  • PatchDay Alert@patchdayalert
    Disclosure

    Zyxel fixed CVE-2024-11667 before customers knew what to look for. That is the disclosure failure operators hate most: the patch exists, the exploitation exists, and the signal arrives late. https://patchdayalert.com/blog/zyxel-cve-2024-11667-silent-patch/

    Post summary

    Zyxel issued a patch for CVE‑2024‑11667 before customers were alerted, illustrating a disclosure failure where the exploitation existed but the warning arrived too late.

    0000012
    49 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-11667-multiple-firewalls #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research indicates that CVE‑2024‑11667 is actively exploited against multiple firewalls, yet it provides no patch, exploit code details, or in‑depth technical analysis.

    0000027
    152 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
HWzyxelatp---
HWzyxelatp100---
HWzyxelatp100w---
HWzyxelatp200---
HWzyxelatp500---
HWzyxelatp700---
HWzyxelatp800---
HWzyxelusg_20w-vpn---
HWzyxelusg_flex---
HWzyxelusg_flex_100---
HWzyxelusg_flex_100ax---
HWzyxelusg_flex_100w---
HWzyxelusg_flex_200---
HWzyxelusg_flex_50---
HWzyxelusg_flex_500---
HWzyxelusg_flex_50w---
HWzyxelusg_flex_700---
OSzyxelzld---

Explore more