Executive brief
Zyxel firewalls and AP controllers contain an undocumented administrative account (zyfwp) with a hard-coded, unchangeable password stored in cleartext within the firmware. Remote attackers can exploit this to gain full administrative access to the device via the SSH server or web interface.
Affected products
- Zyxel ATP Series Firewall 4.60
- Zyxel USG Series Firewall 4.60
- Zyxel USG FLEX Series Firewall 4.60
- Zyxel VPN Series Firewall 4.60
- Zyxel NXC2500 AP Controller 6.00 through 6.10
- Zyxel NXC5500 AP Controller 6.00 through 6.10
Timeline
- 2020-12-15: patched: ZLD V4.60 Patch 1 released
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed