Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls
CVE: CVE-2026-14818
Summary
Zyxel has released patches to address a path traversal vulnerability in certain versions of its ZLD firewall firmware. Users are advised to install these patches promptly to ensure optimal protection.
What is the vulnerability?
CVE-2026-14818
A path traversal vulnerability in the CLI command used to execute configuration files in certain versions of ZLD firewall firmware could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.
What versions are vulnerable—and what should you do?
After a thorough investigation, we identified the vulnerable ZLD firewall firmware versions and released patches for models still within their vulnerability support period, as shown in the table below. Please note that on-market products not listed in the table remain unaffected.
| Firewall series | Affected version | Patch availability |
|---|---|---|
| ATP | ZLD V4.32 to V5.42 Patch 1 | ZLD V5.43 |
| USG FLEX | ZLD V4.50 to V5.42 Patch 1 | ZLD V5.43 |
| USG FLEX 50(W)/USG20(W)-VPN | ZLD V4.16 to V5.42 Patch 1 | ZLD V5.43 |
Got a question?
Please contact your local service rep or visit Zyxel's Community for further information or assistance.
Revision history
2026-8-4: Initial release