10
CVE-2020-29583
- EPSS 90.16%
- Veröffentlicht 22.12.2020 22:15:14
- Zuletzt bearbeitet 07.11.2025 22:03:10
- Erkennungen
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zyxel ≫ Usg20-vpn Firmware Version 4.60
Zyxel ≫ Usg20w-vpn Firmware Version 4.60
Zyxel ≫ Usg40 Firmware Version 4.60
Zyxel ≫ Usg40w Firmware Version 4.60
Zyxel ≫ Usg60 Firmware Version 4.60
Zyxel ≫ Usg60w Firmware Version 4.60
Zyxel ≫ Usg110 Firmware Version 4.60
Zyxel ≫ Usg210 Firmware Version 4.60
Zyxel ≫ Usg310 Firmware Version 4.60
Zyxel ≫ Usg1100 Firmware Version 4.60
Zyxel ≫ Usg1900 Firmware Version 4.60
Zyxel ≫ Usg2200 Firmware Version 4.60
Zyxel ≫ Zywall110 Firmware Version 4.60
Zyxel ≫ Zywall310 Firmware Version 4.60
Zyxel ≫ Zywall1100 Firmware Version 4.60
Zyxel ≫ Atp100 Firmware Version 4.60
Zyxel ≫ Atp100w Firmware Version 4.60
Zyxel ≫ Atp200 Firmware Version 4.60
Zyxel ≫ Atp500 Firmware Version 4.60
Zyxel ≫ Atp700 Firmware Version 4.60
Zyxel ≫ Atp800 Firmware Version 4.60
Zyxel ≫ Vpn50 Firmware Version 4.60
Zyxel ≫ Vpn100 Firmware Version 4.60
Zyxel ≫ Vpn300 Firmware Version 4.60
Zyxel ≫ Vpn1000 Firmware Version 4.60
Zyxel ≫ Usg Flex 100 Firmware Version 4.60
Zyxel ≫ Usg Flex 100w Firmware Version 4.60
Zyxel ≫ Usg Flex 200 Firmware Version 4.60
Zyxel ≫ Usg Flex 500 Firmware Version 4.60
Zyxel ≫ Usg Flex 700 Firmware Version 4.60
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
SchwachstelleZyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 90.16% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://www.zyxel.com/support/security_advisories.shtml
http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf
https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release
https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15
https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/
https://www.zyxel.com/support/CVE-2020-29583.shtml
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29583