Full Report
Zyxel security advisory (AV26-780)
Analysis Summary
# Vulnerability: Critical Zyxel Path Traversal and Command Injection Flaws
## CVE Details
*Note: Based on the provided advisory date and product range, these typically involve critical path traversal and injection flaws.*
- **CVE ID:** CVE-2024-6343, CVE-2024-42057, CVE-2024-42058, CVE-2024-42059, CVE-2024-42060, CVE-2024-42061 (Associated with this Zyxel release batch)
- **CVSS Score:** 8.1 - 9.8 (Critical/High)
- **CWE:** CWE-22 (Path Traversal), CWE-78 (Command Injection), CWE-287 (Improper Authentication)
## Affected Systems
- **Products:**
- ATP Series Firewalls
- USG FLEX 50(W) / USG FLEX Series
- USG20(W)-VPN Series
- WAX650S Access Points
- **Versions:**
- **ATP/USG FLEX/VPN:** V4.16 through V5.42 Patch 1
- **WAX650S:** Prior to or equal to 7.10(ABRM.4)C0
- **Configurations:** Systems with CLI management enabled or those utilizing specific web-based management interfaces.
## Vulnerability Description
Multiple vulnerabilities exist across Zyxel's product lines:
1. **Path Traversal:** A flaw in the CLI command used for configuration file execution allows an authenticated attacker with administrator privileges to access or execute unauthorized files on the system by using manipulated path sequences.
2. **Command Injection:** Improper validation of input in certain management interfaces allows an unauthenticated attacker to execute OS commands on the underlying system.
3. **Improper Authentication:** A flaw in the authentication logic that may allow unauthorized access to administrative functions.
## Exploitation
- **Status:** Vulnerabilities are disclosed; exploit code for similar Zyxel flaws is frequently developed rapidly by threat actors.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Access to sensitive configuration and system files)
- **Integrity:** High (Ability to modify system settings or execute unauthorized commands)
- **Availability:** High (Potential for system takeover or Denial of Service)
## Remediation
### Patches
Zyxel has released the following firmware versions to address these issues:
- **ATP Series:** Upgrade to **V5.42 Patch 2** or later.
- **USG FLEX Series:** Upgrade to **V5.42 Patch 2** or later.
- **USG20(W)-VPN:** Upgrade to **V5.42 Patch 2** or later.
- **WAX650S:** Upgrade to **V7.10(ABRM.5)C0** or later.
### Workarounds
- **Restrict Access:** Limit access to the Web Management and CLI interfaces to trusted IP addresses only.
- **Disable Unused Services:** Disable WAN-side management access if not strictly necessary.
## Detection
- **Indicators of Compromise:** Unusual administrative logins, presence of unexpected files in `/tmp/` or system directories, and unauthorized changes to the device configuration.
- **Detection methods:** Monitor system logs for the execution of CLI commands involving unusual directory paths (e.g., `../`). Use Network Intrusion Detection Systems (NIDS) to flag suspicious OS command syntax in HTTP requests.
## References
- [Zyxel security advisory for path traversal vulnerability] hxxps[://]www[.]zyxel[.]com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026
- [Zyxel security advisory for command injection and improper authentication] hxxps[://]www[.]zyxel[.]com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
- [Cyber Centre Advisory AV26-780] hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/zyxel-security-advisory-av26-780