EXPOSURES › CVE-2024-11667
CVE-2024-11667
CRITICAL ⌖ ON CISA KEV · EXPLOITEDZyxel firewalls had a path traversal flaw in their web management interface that allowed attackers to upload or download files via crafted URLs.
This path traversal vulnerability in Zyxel firewalls allowed attackers to manipulate URLs to upload or download files, potentially leading to unauthorized access or malware deployment. DIB organizations must ensure all network hardware is patched against known CVEs, as unpatched flaws in critical infrastructure like firewalls can be exploited in the wild to compromise network perimeters. Immediate action includes verifying patch levels on all Zyxel devices and monitoring for signs of unauthorized file manipulation.
Shame score — A critical path traversal flaw in widely deployed firewalls was actively exploited in the wild and linked to ransomware, indicating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.