CVE-2024-11667
published 2024-11-27CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-12-24
Exploited in the wild
EPSS
3.02%
85.9th percentile
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20_vpn_series_firmware | — | — |
| zyxel | usg_flex_50_series_firmware | — | — |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | zld | 5.00 – 5.38 | — |
| zyxel | zld | 5.10 – 5.38 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for creation of suspicious local user account named 'OKSDW82A' on Zyxel firewall devices, which was used to establish SSL VPN sessions into victim networks. ↗
- →Monitor for presence of 'zzz1.conf' configuration file on MIPS-based Zyxel firewall devices, indicative of attacker-staged configuration for exploitation. ↗
- →Detect crafted URL-based directory traversal attempts against the Zyxel web management interface (ZLD firmware V5.00–V5.38) that attempt to download or upload files. ↗
- →Hunt for ELF binaries compiled for MIPS architecture uploaded or present on Zyxel firewall devices, potentially base64-encoded in transit, as observed in VirusTotal submissions from Russia between October 17–22, 2024. ↗
- →After firewall compromise, monitor for SSL VPN logins from the rogue account followed by lateral movement to domain controllers and disabling of endpoint defenses. ↗
- →Detect Helldown ransomware activity by looking for batch files used to terminate tasks prior to encryption, and encrypted files with random 8-character extensions accompanied by ransom notes named 'Readme.<ext>.txt'. ↗
- ·CVE-2024-11667 affects Zyxel ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN series only on firmware V5.00–V5.38; firmware V5.39 and later is patched and not vulnerable. ↗
- ·Sekoia attributes Helldown's Zyxel exploitation to CVE-2024-11667 (directory traversal) and possibly CVE-2024-42057 (IPSec VPN command injection) with only medium confidence; a separate undocumented vulnerability was also reported to Zyxel PSIRT. ↗
- ·The observed MIPS ELF payload uploaded to VirusTotal was incomplete, so its full capability and definitive link to Zyxel exploitation is assessed only with medium confidence. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck7.5HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Zyxel Multiple Firewalls Path Traversal Vulnerability
cisa·2024-12-03·CVSS 9.8
CVE-2024-11667 [CRITICAL] CWE-22 Zyxel Multiple Firewalls Path Traversal Vulnerability
Vulnerability: Zyxel Multiple Firewalls Path Traversal Vulnerability
Affected: Zyxel Multiple Firewalls
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-21-2024 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11667
Remediation Due Date: 2024-12-24
GHSA
GHSA-h9fh-gm4r-6cxh: A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5
ghsa_unreviewed·2024-11-27
CVE-2024-11667 [HIGH] CWE-22 GHSA-h9fh-gm4r-6cxh: A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
VulnCheck
Zyxel Multiple Firewalls Path Traversal Vulnerability
vulncheck·2024·CVSS 7.5
CVE-2024-11667 [HIGH] CWE-22 Zyxel Multiple Firewalls Path Traversal Vulnerability
Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
Affected: Zyxel Multiple Firewalls
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-21-2024; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2024-12-24
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Helldown ransomware exploits Zyxel VPN flaw to breach networks
blogs_bleepingcomputer·2024-11-19
Helldown ransomware exploits Zyxel VPN flaw to breach networks
## Helldown ransomware exploits Zyxel VPN flaw to breach networks
## Bill Toulas
The new 'Helldown' ransomware operation is believed to target vulnerabilities in Zyxel firewalls to breach corporate networks, allowing them to steal data and encrypt devices.
French cybersecurity firm Sekoia is reporting this with medium confidence based on recent observations of Helldown attacks.
Although not among the major players in the ransomware space, Helldown has quickly grown since its launch over the summer, listing numerous victims on its data extortion portal.
## Helldown discovery and overview
Helldown was first documented by Cyfirma on August 9, 2024, and then again by Cyberint on October 13, both briefly describing the new ransomware operation.
The first report of a Linux variant of the
arXiv
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
arxiv_fulltext·2026-03
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Akhil Gupta Chigullapally^1, Sharvan Vittala^1, Razin Farhan Hussian^2, Mohsen Amini Salehi^3
^1Department of Computer Science and Engineering, University of North Texas (UNT)
\akhilguptachigullapally, [email protected]\@my.unt.edu
^2Versaterm Public Safety Inc., Canada
[email protected]
^3High Performance Cloud Computing (HPCC) Lab, Department of Computer Science and Engineering, University of North Texas (UNT)
[email protected]
## Abstract
The fast pace of modern AI is rapidly transforming traditional industrial systems into vast,
intelligent—and potentially unmanned—autonomous operational environments driven by AI-based solutions. These solutions leverage various forms of machine lea
2024-11-27
Published
2024-12-03
Added to CISA KEV
Exploited in the wild