PT-2026-67635 · Zyxel · Usg Flex H Series+3

CVE-2026-14818

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel ATP series versions V4.32 through V5.42 Patch 1 Zyxel USG FLEX series versions V4.50 through V5.42 Patch 1 Zyxel USG FLEX 50(W) series versions V4.16 through V5.42 Patch 1 Zyxel USG20(W)-VPN series versions V4.16 through V5.42 Patch 1
Description A path traversal issue exists in the CLI command used to execute configuration files. This flaw allows an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on the device. Path traversal is a technique used to access files and directories that are stored outside the intended folder by using special characters like dot-dot-slash (../).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14818

Affected Products

Atp Series
Usg Flex 50(W) Series
Usg Flex H Series
Usg20(W)-Vpn Series