ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Backdoor in Zyxel Firewalls and Gateways

highMalwareimportance 42
Full article120 words · extracted from schneier.com · click to collapse

This is bad:

More than 100,000 Zyxel firewalls, VPN gateways, and access point controllers contain a hardcoded admin-level backdoor account that can grant attackers root access to devices via either the SSH interface or the web administration panel.

[…]

Installing patches removes the backdoor account, which, according to Eye Control researchers, uses the “zyfwp” username and the “PrOw!aN_fXp” password.

“The plaintext password was visible in one of the binaries on the system,” the Dutch researchers said in a report published before the Christmas 2020 holiday.

Tags: backdoors, data protection, firewall, hardware, passwords, patching, VPN

Posted on January 6, 2021 at 5:44 AM18 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/01/backdoor-in-zyxel-firewalls-and-gateways.html