CVE-2020-29583
KEV PoC largeHard-Coded 'zyfwp' Admin Backdoor in Zyxel USG Firewall Firmware 4.60
CISA: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Zyxel USG-series firewall/VPN gateway firmware version 4.60 ships with an undocumented built-in account named 'zyfwp' whose password is unchangeable and stored in cleartext in the firmware image, making the credentials effectively public once the firmware is examined (use of hard-coded credentials, CWE-522). An unauthenticated attacker who can reach the device's SSH server or web management interface can log in with these embedded credentials and gain full administrator privileges, enabling configuration changes, theft of credentials or logs, and pivoting into the networks the firewall protects; the flaw scores 9.8 (CVSS 3.1) because it is network-exploitable with no privileges or user interaction required. Affected products are the twelve Zyxel USG models listed by CISA (USG20-VPN through USG2200), widely deployed in small/medium-business, branch-office, and ISP/MSP-managed networks. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile), and a public PoC write-up plus news reports of active attacks against Zyxel firewalls and VPNs are available.
What to do: Upgrade affected USG devices to a firmware release later than 4.60 per Zyxel's advisory (CISA's required action is to apply vendor updates). Until patched, restrict SSH and web management access to trusted networks and review device logs for logins by the 'zyfwp' account, since its password is public and cannot be changed on vulnerable firmware; check for signs of compromise when upgrading.
| Zyxel USG20-VPN firmware | 4.60 |
| Zyxel USG20W-VPN firmware | 4.60 |
| Zyxel USG40 firmware | 4.60 |
| Zyxel USG40W firmware | 4.60 |
| Zyxel USG60 firmware | 4.60 |
| Zyxel USG60W firmware | 4.60 |
| Zyxel USG110 firmware | 4.60 |
| Zyxel USG210 firmware | 4.60 |
| Zyxel USG310 firmware | 4.60 |
| Zyxel USG1100 firmware | 4.60 |
| Zyxel USG1900 firmware | 4.60 |
| Zyxel USG2200 firmware | 4.60 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
- Affected
- Zyxel Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zyxel
- Products
- usg20-vpn firmware, usg20w-vpn firmware, usg40 firmware, usg40w firmware, usg60 firmware, usg60w firmware, usg110 firmware, usg210 firmware, usg310 firmware, usg1100 firmware, usg1900 firmware, usg2200 firmware
- Weakness
- CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H