CVE-2020-29583
Description
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Summary dbcve.org
Zyxel USG devices running firmware version 4.60 contain an undocumented administrative account (zyfwp) with a hardcoded, cleartext password embedded directly in the firmware image. Attackers who obtain the firmware through extraction or other means can use these credentials to authenticate to the device's SSH server or web interface with full admin privileges.
Mitigation
Upgrade to a patched firmware version that removes the undocumented account; if an immediate patch is unavailable, disable SSH and web interface access from untrusted networks and implement monitoring for unauthorized access attempts.