PT-2026-67635 · Zyxel · Usg Flex H Series+3
CVE-2026-14818
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel ATP series versions V4.32 through V5.42 Patch 1
Zyxel USG FLEX series versions V4.50 through V5.42 Patch 1
Zyxel USG FLEX 50(W) series versions V4.16 through V5.42 Patch 1
Zyxel USG20(W)-VPN series versions V4.16 through V5.42 Patch 1
Description
A path traversal issue exists in the CLI command used to execute configuration files. This flaw allows an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on the device. Path traversal is a technique used to access files and directories that are stored outside the intended folder by using special characters like dot-dot-slash (../).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atp Series
Usg Flex 50(W) Series
Usg Flex H Series
Usg20(W)-Vpn Series