CVE-2020-29583
Summary
| CVE | CVE-2020-29583 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-22 22:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges. |
Risk And Classification
EPSS: 0.943670000 probability, percentile 0.999640000 (date 2026-04-01)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-522
CISA Known Exploited Vulnerability
| Vendor | Zyxel |
|---|---|
| Product | Multiple Products |
| Name | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-29583 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zyxel | Usg110 | - | All | All | All |
| Hardware | Zyxel | Usg110 | - | All | All | All |
| Hardware | Zyxel | Usg1100 | - | All | All | All |
| Hardware | Zyxel | Usg1100 | - | All | All | All |
| Operating System | Zyxel | Usg1100 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg1100 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg110 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg110 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg1900 | - | All | All | All |
| Hardware | Zyxel | Usg1900 | - | All | All | All |
| Operating System | Zyxel | Usg1900 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg1900 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg20-vpn | - | All | All | All |
| Hardware | Zyxel | Usg20-vpn | - | All | All | All |
| Operating System | Zyxel | Usg20-vpn Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg20-vpn Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg20w-vpn | - | All | All | All |
| Hardware | Zyxel | Usg20w-vpn | - | All | All | All |
| Operating System | Zyxel | Usg20w-vpn Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg20w-vpn Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg210 | - | All | All | All |
| Hardware | Zyxel | Usg210 | - | All | All | All |
| Operating System | Zyxel | Usg210 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg210 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg2200 | - | All | All | All |
| Hardware | Zyxel | Usg2200 | - | All | All | All |
| Operating System | Zyxel | Usg2200 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg2200 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg310 | - | All | All | All |
| Hardware | Zyxel | Usg310 | - | All | All | All |
| Operating System | Zyxel | Usg310 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg310 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg40 | - | All | All | All |
| Hardware | Zyxel | Usg40 | - | All | All | All |
| Hardware | Zyxel | Usg40w | - | All | All | All |
| Hardware | Zyxel | Usg40w | - | All | All | All |
| Operating System | Zyxel | Usg40w Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg40w Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg40 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg40 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Usg60 | - | All | All | All |
| Hardware | Zyxel | Usg60 | - | All | All | All |
| Hardware | Zyxel | Usg60w | - | All | All | All |
| Hardware | Zyxel | Usg60w | - | All | All | All |
| Operating System | Zyxel | Usg60w Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg60w Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg60 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Usg60 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Zywall110 | - | All | All | All |
| Hardware | Zyxel | Zywall110 | - | All | All | All |
| Hardware | Zyxel | Zywall1100 | - | All | All | All |
| Hardware | Zyxel | Zywall1100 | - | All | All | All |
| Operating System | Zyxel | Zywall1100 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Zywall1100 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Zywall110 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Zywall110 Firmware | 4.60 | All | All | All |
| Hardware | Zyxel | Zywall310 | - | All | All | All |
| Hardware | Zyxel | Zywall310 | - | All | All | All |
| Operating System | Zyxel | Zywall310 Firmware | 4.60 | All | All | All |
| Operating System | Zyxel | Zywall310 Firmware | 4.60 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.zyxel.com/USG40/firmware/USG40_4.60(AALA.1)C0_2.pdf | CONFIRM | ftp.zyxel.com | Vendor Advisory |
| ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf | ftp.zyxel.com | ||
| Zyxel security advisory for hardcoded credential vulnerability | Zyxel | CONFIRM | www.zyxel.com | Vendor Advisory |
| Security Advisories | Zyxel | MISC | www.zyxel.com | Vendor Advisory |
| Secret Backdoor to Zyxel Firewall and AP Controllers Could Allow Administrative Access - SecPod Blog | MISC | www.secpod.com | |
| Undocumented user account in Zyxel products (CVE-2020-29583) - EYE | MISC | www.eyecontrol.nl | Third Party Advisory |
| ZLD v4.60 Revoke and WK48 Firmware release — Zyxel | MISC | businessforum.zyxel.com | Release Notes, Vendor Advisory |
| What's New for ZLD4.60 patch 1 (available on Dec. 15) — Zyxel | MISC | businessforum.zyxel.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.