CRITICAL · 9.8

CVE-2020-29583

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account...

Vulnerability Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelUsg20-Vpn Firmware4.60
ZyxelUsg20-Vpn-
ZyxelUsg20W-Vpn Firmware4.60
ZyxelUsg20W-Vpn-
ZyxelUsg40 Firmware4.60
ZyxelUsg40-
ZyxelUsg40W Firmware4.60
ZyxelUsg40W-
ZyxelUsg60 Firmware4.60
ZyxelUsg60-
ZyxelUsg60W Firmware4.60
ZyxelUsg60W-
ZyxelUsg110 Firmware4.60
ZyxelUsg110-
ZyxelUsg210 Firmware4.60
ZyxelUsg210-
ZyxelUsg310 Firmware4.60
ZyxelUsg310-
ZyxelUsg1100 Firmware4.60
ZyxelUsg1100-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-29583?

CVE-2020-29583 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account...

How severe is CVE-2020-29583?

CVE-2020-29583 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-29583?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Usg20-Vpn Firmware, Zyxel Usg20-Vpn, Zyxel Usg20W-Vpn Firmware, Zyxel Usg20W-Vpn, Zyxel Usg40 Firmware.