CRITICAL

CVE-2020-29583

Zyxel Usg20 Vpn Firmware 2020-12-22 CVSS v3.1
CVSS
9.8
KEV

Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Summary dbcve.org

Zyxel USG devices running firmware version 4.60 contain an undocumented administrative account (zyfwp) with a hardcoded, cleartext password embedded directly in the firmware image. Attackers who obtain the firmware through extraction or other means can use these credentials to authenticate to the device's SSH server or web interface with full admin privileges.

Mitigation

Upgrade to a patched firmware version that removes the undocumented account; if an immediate patch is unavailable, disable SSH and web interface access from untrusted networks and implement monitoring for unauthorized access attempts.

Proof of Concept

Weakness (CWE)

CWE-522 Insufficiently Protected Credentials

EPSS Score

90.16%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE