Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-14818PATCHED
zyxel · atp series firmware

CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi

Description

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.

Affected Products

VendorProductVersions
zyxelatp series firmwarefrom V4.32 through V5.42 Patch 1, from V4.50 through V5.42 Patch 1, from V4.16 through V5.42 Patch 1, from V4.16 through V5.42 Patch 1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
zyxelfirewallcert_advisory90%

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories8d ago
[NEU] [mittel] Zyxel Firewall: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
VulDB8d ago
CVE-2026-14818 | Zyxel ATP/USG FLEX/USG FLEX 50(W)/USG20(W)-VPN path traversal
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026
CWECWE-22
PublishedAug 4, 2026
Trending Score15
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Trending: 33
HIGHCVE-2026-12984
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
Trending: 27
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router
Trending: 23
MEDIUMCVE-2026-6373
Sensitive Data Exposure in Zyxel WAH7601 Router
Trending: 15
HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 10

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026
Patch Available
Aug 4, 2026