Junglewise Threat Intelligence

CVE-2020-29583: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

CVE-2020-29583 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Zyxel.

Executive brief

Zyxel firewalls and AP controllers contain an undocumented administrative account (zyfwp) with a hard-coded, unchangeable password stored in cleartext within the firmware. Remote attackers can exploit this to gain full administrative access to the device via the SSH server or web interface.

Affected products

  • Zyxel ATP Series Firewall 4.60
  • Zyxel USG Series Firewall 4.60
  • Zyxel USG FLEX Series Firewall 4.60
  • Zyxel VPN Series Firewall 4.60
  • Zyxel NXC2500 AP Controller 6.00 through 6.10
  • Zyxel NXC5500 AP Controller 6.00 through 6.10

Timeline

  • 2020-12-15: patched: ZLD V4.60 Patch 1 released
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed