CVE-2026-14818
Zyxel ATP and USG FLEX Series Firmware Path Traversal Vulnerability
Record summary
CVE-2026-14818 has a selected CVSS score of 7.2 (high).
Description
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
ATP series firmwareBrowse Zyxel / ATP series firmwareDefault status: unaffected | CVE List | from V4.32 through V5.42 Patch 1 | affected |
USG FLEX 50(W) series firmwareBrowse Zyxel / USG FLEX 50(W) series firmwareDefault status: unaffected | CVE List | from V4.16 through V5.42 Patch 1 | affected |
USG FLEX series firmwareBrowse Zyxel / USG FLEX series firmwareDefault status: unaffected | CVE List | from V4.50 through V5.42 Patch 1 | affected |
USG20(W)-VPN series firmwareBrowse Zyxel / USG20(W)-VPN series firmwareDefault status: unaffected | CVE List | from V4.16 through V5.42 Patch 1 | affected |