Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-29583 | Hard-Coded 'zyfwp' Admin Backdoor in Zyxel USG Firewall Firmware 4.60 Zyxel USG-series firewall/VPN gateway firmware version 4.60 ships with an undocumented built-in account named 'zyfwp' whose password is unchangeable and stored in cleartext in the firmware image, making the credentials effectively public once the firmware is examined (use of hard-coded credentials, CWE-522). An unauthenticated attacker who can reach the device's SSH server or web management interface can log in with these embedded credentials and gain full administrator privileges, enabling configuration changes, theft of credentials or logs, and pivoting into the networks the firewall protects; the flaw scores 9.8 (CVSS 3.1) because it is network-exploitable with no privileges or user interaction required. Affected products are the twelve Zyxel USG models listed by CISA (USG20-VPN through USG2200), widely deployed in small/medium-business, branch-office, and ISP/MSP-managed networks. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile), and a public PoC write-up plus news reports of active attacks against Zyxel firewalls and VPNs are available. Do: Upgrade affected USG devices to a firmware release later than 4.60 per Zyxel's advisory (CISA's required action is to apply vendor updates). Until patched, restrict SSH and web management access to trusted networks and review device logs for logins by the 'zyfwp' account, since its password is public and cannot be changed on vulnerable firmware; check for signs of compromise when upgrading. | 9.8 | 90% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel USG firewalls (order 10^4-10^5 devices; total installed base likely higher) |
Full article334 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 01, 2021
Zyxel has released a patch to address a critical vulnerability in its firmware concerning a hardcoded, undocumented secret account that could be abused by an attacker to login with administrative privileges and compromise its networking devices.
The flaw, tracked as CVE-2020-29583 (CVSS score 7.8), affects version 4.60 present in a wide-range of Zyxel devices, including Unified Security Gateway (USG), USG FLEX, ATP, and VPN firewall products.
EYE researcher Niels Teusink reported the vulnerability to Zyxel on November 29, following which the company released a firmware patch (ZLD V4.60 Patch1) on December 18.
According to the advisory published by Zyxel, the undocumented account ("zyfwp") comes with an unchangeable password that's not only stored in plaintext but could also be used by a malicious third-party to login to the SSH server or web interface with admin privileges.
Zyxel said the hardcoded credentials were put in place to deliver automatic firmware updates to connected access points through FTP.
Noting that around 10% of 1000 devices in the Netherlands run the affected firmware version, Teusink said the flaw's relative ease of exploitation makes it a critical vulnerability.
"As the 'zyfwp' user has admin privileges, this is a serious vulnerability," Teusink said in a write-up. "An attacker could completely compromise the confidentiality, integrity and availability of the device."
"Someone could for example change firewall settings to allow or block certain traffic. They could also intercept traffic or create VPN accounts to gain access to the network behind the device. Combined with a vulnerability like Zerologon this could be devastating to small and medium businesses."
The Taiwanese company is also expected to address the issue in its access point (AP) controllers with a V6.10 Patch1 that's set to be released in April 2021.
It's highly recommended that users install the necessary firmware updates to mitigate the risk associated with the flaw.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/01/secret-backdoor-account-found-in.html