Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in Zyxel Network Appliance CLI

An authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.

A path traversal vulnerability exists in the CLI command handler responsible for processing configuration files within Zyxel network security appliances. This vulnerability, tracked as CVE-2026-14818, affects the ATP series (versions V4.32 through V5.42 Patch 1), USG FLEX series (versions V4.50 through V5.42 Patch 1), USG FLEX 50(W) series (versions V4.16 through V5.42 Patch 1), and USG20(W)-VPN series (versions V4.16 through V5.42 Patch 1). An attacker who has already gained administrative authentication to the device can leverage this flaw to traverse directories and execute a specially crafted configuration file. Successful exploitation results in the execution of arbitrary commands, allowing the attacker to alter the device configuration or achieve persistent system access. Defenders should prioritize updating firmware to versions V5.42 Patch 2 or later, where this path handling logic has been remediated.


Immediate actions

Patch firmware to V5.42 Patch 2 or higher on all Zyxel appliances.

IT Operations 72h

Mitigations

Restrict administrative access to authorized IP addresses.

immediate Network Security

CVE-2026-14818