Impact
A path traversal flaw exists in the command-line interface that initiates the execution of configuration files on Zyxel firewall devices. The weakness allows an authenticated attacker with administrator privileges to supply a crafted configuration file path that resolves outside the expected directory, enabling the device to load and run the attacker’s file. Because the file can contain arbitrary configuration directives and potentially commands, the vulnerability provides a gateway for malicious configuration changes. Based on the description, it is inferred that the attacker could achieve remote code execution or significant configuration tampering, compromising the device’s integrity and availability.
Affected Systems
Zyxel ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, and USG20(W)-VPN series firmware. The affected ranges are V4.32 to V5.42 Patch 1 for ATP; V4.50 to V5.42 Patch 1 for USG FLEX; V4.16 to V5.42 Patch 1 for USG FLEX 50(W); and V4.16 to V5.42 Patch 1 for USG20(W)-VPN.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk. The exploit requires authenticated access with administrative credentials, which may be obtained through phishing or credential compromise. Although the EPSS score is not publicly available, the absence of a KEV listing does not diminish the potential for widespread impact, especially in environments where these firewalls control critical network segments. Based on the description, it is inferred that an attacker who succeeds could alter firewall policies, redirect traffic, or embed unwanted functionality, leading to significant operational disruptions.
OpenCVE Enrichment