What is CVE-2026-14818?
This critical vulnerability allows a path traversal attack via the CLI command used to execute configuration files in Zyxel security appliances. Affected devices include specific firmware versions of the ATP, USG FLEX, and USG FLEX 50(W) series. Immediate patching with the vendor's update is strongly recommended.
Azərbaycanca: Bu kritik zəiflik Zyxel təhlükəsizlik cihazlarının CLI interfeysində konfiqurasiya fayllarının yüklənməsi zamanı yol keçidi (path traversal) hücumuna imkan verir. Təsirə məruz qalan qurğulara ATP, USG FLEX və USG FLEX 50(W) seriyalarının müəyyən proqram versiyaları daxildir. Təcili olaraq istehsalçı tərəfindən təqdim edilmiş patchi tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which Zyxel devices are affected by CVE-2026-14818?
This vulnerability affects specific firmware versions of Zyxel's ATP, USG FLEX, and USG FLEX 50(W) series security appliances.
What is the primary mitigation for CVE-2026-14818?
Immediate patching with the vendor's update is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.