Answer in brief
CVE-2024-11667 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps zyxel/atp_firmware (generic), Zyxel/ATP series firmware (generic), zyxel/usg20-vpn_firmware (generic), Zyxel/USG20(W)-VPN series firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps zyxel/atp_firmware (generic), Zyxel/ATP series firmware (generic), zyxel/usg20-vpn_firmware (generic), Zyxel/USG20(W)-VPN series firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| zyxel/atp_firmwaregeneric | 5.00 | Not reported |
| Zyxel/ATP series firmwaregeneric | versions V5.00 through V5.38 | Not reported |
| zyxel/usg20-vpn_firmwaregeneric | 5.10 | Not reported |
| Zyxel/USG20(W)-VPN series firmwaregeneric | versions V5.10 through V5.38 | Not reported |
| zyxel/usg_flex_50w_firmwaregeneric | >=5.10 <5.38 | 5.38 |
| Zyxel/USG FLEX 50(W) series firmwaregeneric | versions V5.10 through V5.38 | Not reported |
| zyxel/usg_flex_firmwaregeneric | 5.00 | Not reported |
| Zyxel/USG FLEX series firmwaregeneric | versions V5.00 through V5.38 | Not reported |
Published upstream
Nov 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 3, 2024
Evidence: source:kev:kev:kev:recordA directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-11667 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps zyxel/atp_firmware (generic), Zyxel/ATP series firmware (generic), zyxel/usg20-vpn_firmware (generic), Zyxel/USG20(W)-VPN series firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps zyxel/atp_firmware (generic), Zyxel/ATP series firmware (generic), zyxel/usg20-vpn_firmware (generic), Zyxel/USG20(W)-VPN series firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| zyxel/atp_firmwaregeneric | 5.00 | Not reported |
| Zyxel/ATP series firmwaregeneric | versions V5.00 through V5.38 | Not reported |
| zyxel/usg20-vpn_firmwaregeneric | 5.10 | Not reported |
| Zyxel/USG20(W)-VPN series firmwaregeneric | versions V5.10 through V5.38 | Not reported |
| zyxel/usg_flex_50w_firmwaregeneric | >=5.10 <5.38 | 5.38 |
| Zyxel/USG FLEX 50(W) series firmwaregeneric | versions V5.10 through V5.38 | Not reported |
| zyxel/usg_flex_firmwaregeneric | 5.00 | Not reported |
| Zyxel/USG FLEX series firmwaregeneric | versions V5.00 through V5.38 | Not reported |
Published upstream
Nov 27, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 3, 2024
Evidence: source:kev:kev:kev:recordA directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Quoted source text, attributed separately from HOL analysis.