ZeroHour

CVE-2020-29583

KEV PoC large

Hard-Coded 'zyfwp' Admin Backdoor in Zyxel USG Firewall Firmware 4.60

CISA: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

CVSS 3.1
9.8 critical
EPSS
90%p100
Published
()
KEV added
AI analysis

Zyxel USG-series firewall/VPN gateway firmware version 4.60 ships with an undocumented built-in account named 'zyfwp' whose password is unchangeable and stored in cleartext in the firmware image, making the credentials effectively public once the firmware is examined (use of hard-coded credentials, CWE-522). An unauthenticated attacker who can reach the device's SSH server or web management interface can log in with these embedded credentials and gain full administrator privileges, enabling configuration changes, theft of credentials or logs, and pivoting into the networks the firewall protects; the flaw scores 9.8 (CVSS 3.1) because it is network-exploitable with no privileges or user interaction required. Affected products are the twelve Zyxel USG models listed by CISA (USG20-VPN through USG2200), widely deployed in small/medium-business, branch-office, and ISP/MSP-managed networks. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile), and a public PoC write-up plus news reports of active attacks against Zyxel firewalls and VPNs are available.

What to do: Upgrade affected USG devices to a firmware release later than 4.60 per Zyxel's advisory (CISA's required action is to apply vendor updates). Until patched, restrict SSH and web management access to trusted networks and review device logs for logins by the 'zyfwp' account, since its password is public and cannot be changed on vulnerable firmware; check for signs of compromise when upgrading.

Affected
Zyxel USG20-VPN firmware4.60
Zyxel USG20W-VPN firmware4.60
Zyxel USG40 firmware4.60
Zyxel USG40W firmware4.60
Zyxel USG60 firmware4.60
Zyxel USG60W firmware4.60
Zyxel USG110 firmware4.60
Zyxel USG210 firmware4.60
Zyxel USG310 firmware4.60
Zyxel USG1100 firmware4.60
Zyxel USG1900 firmware4.60
Zyxel USG2200 firmware4.60
Estimated exposure
largetens of thousands of internet-exposed Zyxel USG firewalls (order 10^4-10^5 devices; total installed base likely higher) — Estimated from internet-wide scan counts of exposed Zyxel firewall/VPN gateways around the time of disclosure and the USG series' broad SMB/MSP deployment footprint, with exposure limited to devices whose SSH or web management interface is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

CISA Known Exploited Vulnerability
Affected
Zyxel Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
usg20-vpn firmware, usg20w-vpn firmware, usg40 firmware, usg40w firmware, usg60 firmware, usg60w firmware, usg110 firmware, usg210 firmware, usg310 firmware, usg1100 firmware, usg1900 firmware, usg2200 firmware
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news