cbcvebase.
CVE-2024-11667
published 2024-11-27

CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware…

PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-12-24
Exploited in the wild
EPSS
3.02%
85.9th percentile
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

Affected

6 ranges
VendorProductVersion rangeFixed in
zyxelatp_series_firmware
zyxelusg20_vpn_series_firmware
zyxelusg_flex_50_series_firmware
zyxelusg_flex_series_firmware
zyxelzld5.00 – 5.38
zyxelzld5.10 – 5.38

Detection & IOCsextracted from sources · hover to see the quote

filenamezzz1.conf
otherFGqogsxF
filenameReadme.FGqogsxF.txt
  • Look for creation of suspicious local user account named 'OKSDW82A' on Zyxel firewall devices, which was used to establish SSL VPN sessions into victim networks.
  • Monitor for presence of 'zzz1.conf' configuration file on MIPS-based Zyxel firewall devices, indicative of attacker-staged configuration for exploitation.
  • Detect crafted URL-based directory traversal attempts against the Zyxel web management interface (ZLD firmware V5.00–V5.38) that attempt to download or upload files.
  • Hunt for ELF binaries compiled for MIPS architecture uploaded or present on Zyxel firewall devices, potentially base64-encoded in transit, as observed in VirusTotal submissions from Russia between October 17–22, 2024.
  • After firewall compromise, monitor for SSL VPN logins from the rogue account followed by lateral movement to domain controllers and disabling of endpoint defenses.
  • Detect Helldown ransomware activity by looking for batch files used to terminate tasks prior to encryption, and encrypted files with random 8-character extensions accompanied by ransom notes named 'Readme.<ext>.txt'.
  • ·CVE-2024-11667 affects Zyxel ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN series only on firmware V5.00–V5.38; firmware V5.39 and later is patched and not vulnerable.
  • ·Sekoia attributes Helldown's Zyxel exploitation to CVE-2024-11667 (directory traversal) and possibly CVE-2024-42057 (IPSec VPN command injection) with only medium confidence; a separate undocumented vulnerability was also reported to Zyxel PSIRT.
  • ·The observed MIPS ELF payload uploaded to VirusTotal was incomplete, so its full capability and definitive link to Zyxel exploitation is assessed only with medium confidence.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck7.5HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.