CVE-2020-29583
zyxel usg20-vpn firmware, zyxel usg20w-vpn firmware, zyxel usg40 firmware
Published 22 Dec 2020 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
References
- ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf · Broken Link
- businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release · Release Notes
- businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15 · Release Notes
- www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html · Broken Link, Third Party Advisory
- www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/ · Exploit, Third Party Advisory
- www.zyxel.com/support/CVE-2020-29583.shtml · Vendor Advisory
- www.zyxel.com/support/security_advisories.shtml · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29583 · US Government Resource