CVE-2026-14818
Received
Received - Intake
Path Traversal in Zyxel ATP Series Firmware
Vulnerability report for CVE-2026-14818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-04
Last updated on: 2026-08-04
Assigner: Zyxel Corporation
Description
Description
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zyxel | atp_series_firmware | From 4.32 (inc) to 5.42 (inc) |
| zyxel | usg_flex_series_firmware | From 4.50 (inc) to 5.42 (inc) |
| zyxel | usg_flex_50w_series_firmware | From 4.16 (inc) to 5.42 (inc) |
| zyxel | usg20w_vpn_series_firmware | From 4.16 (inc) to 5.42 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |