{
  "id": "CVE-2020-29583",
  "url": "https://spydr.io/cve/CVE-2020-29583",
  "published": "2020-12-22T22:15:14.443Z",
  "modified": "2026-06-17T03:11:28.957Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.90155,
  "epss_percentile": 0.99796,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-29583"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "zyxel"
  ],
  "products": [
    "zyxel usg20-vpn firmware",
    "zyxel usg20w-vpn firmware",
    "zyxel usg40 firmware",
    "zyxel usg40w firmware",
    "zyxel usg60 firmware",
    "zyxel usg60w firmware",
    "zyxel usg110 firmware",
    "zyxel usg210 firmware",
    "zyxel usg310 firmware",
    "zyxel usg1100 firmware",
    "zyxel usg1900 firmware",
    "zyxel usg2200 firmware",
    "zyxel zywall110 firmware",
    "zyxel zywall310 firmware",
    "zyxel zywall1100 firmware",
    "zyxel atp100 firmware",
    "zyxel atp100w firmware",
    "zyxel atp200 firmware",
    "zyxel atp500 firmware",
    "zyxel atp700 firmware"
  ],
  "cwes": [
    "CWE-522"
  ],
  "description": "Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.zyxel.com/support/CVE-2020-29583.shtml",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.zyxel.com/support/security_advisories.shtml",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29583",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29583",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
