CVE-2020-29583 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 90.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 90.16% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2020-12-22 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Zyxel / Multiple Products |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| zyxel | atp100 |
| zyxel | atp100 firmware |
| zyxel | atp100w |
| zyxel | atp100w firmware |
| zyxel | atp200 |
| zyxel | atp200 firmware |
| zyxel | atp500 |
| zyxel | atp500 firmware |
| zyxel | atp700 |
| zyxel | atp700 firmware |
| zyxel | usg110 |
| zyxel | usg110 firmware |
| zyxel | usg1100 |
| zyxel | usg1100 firmware |
| zyxel | usg1900 |
| zyxel | usg1900 firmware |
| zyxel | usg20-vpn |
| zyxel | usg20-vpn firmware |
| zyxel | usg20w-vpn |
| zyxel | usg20w-vpn firmware |
| zyxel | usg210 |
| zyxel | usg210 firmware |
| zyxel | usg2200 |
| zyxel | usg2200 firmware |
| zyxel | usg310 |
| zyxel | usg310 firmware |
| zyxel | usg40 |
| zyxel | usg40 firmware |
| zyxel | usg40w |
| zyxel | usg40w firmware |
| zyxel | usg60 |
| zyxel | usg60 firmware |
| zyxel | usg60w |
| zyxel | usg60w firmware |
| zyxel | zywall110 |
| zyxel | zywall110 firmware |
| zyxel | zywall1100 |
| zyxel | zywall1100 firmware |
| zyxel | zywall310 |
| zyxel | zywall310 firmware |
References
- http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf
- https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release
- https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15
- https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
- https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/
- https://www.zyxel.com/support/CVE-2020-29583.shtml
- https://www.zyxel.com/support/security_advisories.shtml
- http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf
- https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release
- https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15
- https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
- https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/
- https://www.zyxel.com/support/CVE-2020-29583.shtml
- https://www.zyxel.com/support/security_advisories.shtml
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29583
→ the Explorer · watch your stack · NVD