10

CVE-2020-29583

Warning
Exploit

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Data is provided by the National Vulnerability Database (NVD)
ZyxelUsg20-vpn Firmware Version4.60
   ZyxelUsg20-vpn Version-
ZyxelUsg20w-vpn Firmware Version4.60
   ZyxelUsg20w-vpn Version-
ZyxelUsg40 Firmware Version4.60
   ZyxelUsg40 Version-
ZyxelUsg40w Firmware Version4.60
   ZyxelUsg40w Version-
ZyxelUsg60 Firmware Version4.60
   ZyxelUsg60 Version-
ZyxelUsg60w Firmware Version4.60
   ZyxelUsg60w Version-
ZyxelUsg110 Firmware Version4.60
   ZyxelUsg110 Version-
ZyxelUsg210 Firmware Version4.60
   ZyxelUsg210 Version-
ZyxelUsg310 Firmware Version4.60
   ZyxelUsg310 Version-
ZyxelUsg1100 Firmware Version4.60
   ZyxelUsg1100 Version-
ZyxelUsg1900 Firmware Version4.60
   ZyxelUsg1900 Version-
ZyxelUsg2200 Firmware Version4.60
   ZyxelUsg2200 Version-
ZyxelZywall110 Firmware Version4.60
   ZyxelZywall110 Version-
ZyxelZywall310 Firmware Version4.60
   ZyxelZywall310 Version-
ZyxelZywall1100 Firmware Version4.60
   ZyxelZywall1100 Version-
ZyxelAtp100 Firmware Version4.60
   ZyxelAtp100 Version-
ZyxelAtp100w Firmware Version4.60
   ZyxelAtp100w Version-
ZyxelAtp200 Firmware Version4.60
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version4.60
   ZyxelAtp500 Version-
ZyxelAtp700 Firmware Version4.60
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version4.60
   ZyxelAtp800 Version-
ZyxelVpn50 Firmware Version4.60
   ZyxelVpn50 Version-
ZyxelVpn100 Firmware Version4.60
   ZyxelVpn100 Version-
ZyxelVpn300 Firmware Version4.60
   ZyxelVpn300 Version-
ZyxelVpn1000 Firmware Version4.60
   ZyxelVpn1000 Version-
ZyxelUsg Flex 100 Firmware Version4.60
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100w Firmware Version4.60
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 200 Firmware Version4.60
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 500 Firmware Version4.60
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 700 Firmware Version4.60
   ZyxelUsg Flex 700 Version-

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

Vulnerability

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.04% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.