Zyxel USG FLEX 50(W) / USG20(W)-VPN 4.16 < 5.43 / ATP 4.32 < 5.43 / USG FLEX 4.50 < 5.43 Path Traversal

high Nessus Plugin ID 335410

Synopsis

The remote security gateway is affected by a path traversal vulnerability.

Description

The firmware version of the Zyxel ZLD firewall device is affected by a path traversal vulnerability. A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Zyxel ZLD firmware version V5.43 or later.

See Also

http://www.nessus.org/u?546bf402

Plugin Details

Severity: High

ID: 335410

File Name: zyxel_usg_cve-2026-14818.nasl

Version: 1.1

Type: Combined

Family: Firewalls

Published: 8/14/2026

Updated: 8/14/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.13

CVSS v2

Risk Factor: High

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2026-14818

CVSS v3

Risk Factor: High

Base Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/h:zyxel:usg_flex

Required KB Items: installed_sw/Zyxel Unified Security Gateway (USG)

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 8/4/2026

Reference Information

CVE: CVE-2026-14818

IAVA: 2026-A-0823