Vulnerability Description
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Usg20-Vpn Firmware | 4.60 |
| Zyxel | Usg20-Vpn | - |
| Zyxel | Usg20W-Vpn Firmware | 4.60 |
| Zyxel | Usg20W-Vpn | - |
| Zyxel | Usg40 Firmware | 4.60 |
| Zyxel | Usg40 | - |
| Zyxel | Usg40W Firmware | 4.60 |
| Zyxel | Usg40W | - |
| Zyxel | Usg60 Firmware | 4.60 |
| Zyxel | Usg60 | - |
| Zyxel | Usg60W Firmware | 4.60 |
| Zyxel | Usg60W | - |
| Zyxel | Usg110 Firmware | 4.60 |
| Zyxel | Usg110 | - |
| Zyxel | Usg210 Firmware | 4.60 |
| Zyxel | Usg210 | - |
| Zyxel | Usg310 Firmware | 4.60 |
| Zyxel | Usg310 | - |
| Zyxel | Usg1100 Firmware | 4.60 |
| Zyxel | Usg1100 | - |
Related Weaknesses (CWE)
References
- http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdfBroken Link
- https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmwaRelease Notes
- https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-avRelease Notes
- https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.htmlBroken LinkThird Party Advisory
- https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allExploitThird Party Advisory
- https://www.zyxel.com/support/CVE-2020-29583.shtmlVendor Advisory
- https://www.zyxel.com/support/security_advisories.shtmlVendor Advisory
- http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdfBroken Link
- https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmwaRelease Notes
- https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-avRelease Notes
- https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.htmlBroken LinkThird Party Advisory
- https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allExploitThird Party Advisory
- https://www.zyxel.com/support/CVE-2020-29583.shtmlVendor Advisory
- https://www.zyxel.com/support/security_advisories.shtmlVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-US Government Resource
FAQ
What is CVE-2020-29583?
CVE-2020-29583 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account...
How severe is CVE-2020-29583?
CVE-2020-29583 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-29583?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Usg20-Vpn Firmware, Zyxel Usg20-Vpn, Zyxel Usg20W-Vpn Firmware, Zyxel Usg20W-Vpn, Zyxel Usg40 Firmware.