irmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
Configuration 17 (hide)
| AND |
|
Configuration 18 (hide)
| AND |
|
Configuration 19 (hide)
| AND |
|
Configuration 20 (hide)
| AND |
|
Configuration 21 (hide)
| AND |
|
Configuration 22 (hide)
| AND |
|
Configuration 23 (hide)
| AND |
|
Configuration 24 (hide)
| AND |
|
Configuration 25 (hide)
| AND |
|
Configuration 26 (hide)
| AND |
|
Configuration 27 (hide)
| AND |
|
Configuration 28 (hide)
| AND |
|
Configuration 29 (hide)
| AND |
|
Configuration 30 (hide)
| AND |
|
07 Nov 2025, 22:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29583 - US Government Resource |
22 Oct 2025, 00:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 05:24
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf - Broken Link | |
| References | () https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release - Release Notes | |
| References | () https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15 - Release Notes | |
| References | () https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html - Broken Link, Third Party Advisory | |
| References | () https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/ - Exploit, Third Party Advisory | |
| References | () https://www.zyxel.com/support/CVE-2020-29583.shtml - Vendor Advisory | |
| References | () https://www.zyxel.com/support/security_advisories.shtml - Vendor Advisory |
26 Jul 2024, 19:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://ftp.zyxel.com/USG40/firmware/USG40_4.60%28AALA.1%29C0_2.pdf - Broken Link | |
| References | () https://businessforum.zyxel.com/discussion/5252/zld-v4-60-revoke-and-wk48-firmware-release - Release Notes | |
| References | () https://businessforum.zyxel.com/discussion/5254/whats-new-for-zld4-60-patch-1-available-on-dec-15 - Release Notes | |
| References | () https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html - Broken Link, Third Party Advisory | |
| References | () https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/ - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp800_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vpn100:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_700_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_100w_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vpn50_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp100w_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vpn1000:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp700_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_200_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vpn100_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp200_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vpn50:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp100_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:atp500_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vpn1000_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vpn300_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_100_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_500_firmware:4.60:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vpn300:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:* |
|
| First Time |
Zyxel usg Flex 500 Firmware
Zyxel atp100 Firmware Zyxel vpn300 Firmware Zyxel vpn1000 Zyxel usg Flex 100 Firmware Zyxel atp100 Zyxel usg Flex 700 Firmware Zyxel usg Flex 700 Zyxel atp500 Firmware Zyxel atp100w Firmware Zyxel vpn50 Zyxel vpn100 Zyxel atp700 Zyxel usg Flex 200 Zyxel vpn300 Zyxel vpn50 Firmware Zyxel atp500 Zyxel atp800 Firmware Zyxel atp700 Firmware Zyxel usg Flex 500 Zyxel vpn100 Firmware Zyxel vpn1000 Firmware Zyxel usg Flex 100 Zyxel atp200 Zyxel atp100w Zyxel usg Flex 200 Firmware Zyxel usg Flex 100w Zyxel atp800 Zyxel atp200 Firmware Zyxel usg Flex 100w Firmware |
Published : 2020-12-22 22:15
Updated : 2025-11-07 22:03
NVD link : CVE-2020-29583
Mitre link : CVE-2020-29583
CVE.ORG link : CVE-2020-29583
JSON object : View
- usg310
- atp200
- usg60w
- usg_flex_500
- vpn50_firmware
- zywall310_firmware
- zywall1100
- usg1100_firmware
- atp100_firmware
- atp700
- usg1900_firmware
- usg_flex_100w
- usg40w_firmware
- usg20-vpn_firmware
- usg110_firmware
- zywall1100_firmware
- vpn100_firmware
- vpn1000
- usg_flex_700_firmware
- usg20w-vpn_firmware
- usg2200
- usg_flex_200
- usg20-vpn
- usg40w
- usg110
- atp700_firmware
- usg_flex_100w_firmware
- usg310_firmware
- usg60w_firmware
- atp200_firmware
- usg60
- zywall110
- atp100w_firmware
- atp800_firmware
- usg_flex_200_firmware
- atp500
- vpn300_firmware
- usg210
- vpn50
- zywall110_firmware
- usg_flex_100_firmware
- usg_flex_700
- vpn1000_firmware
- zywall310
- vpn100
- usg1100
- atp100w
- atp800
- atp100
- vpn300
- usg210_firmware
- usg40_firmware
- usg2200_firmware
- usg40
- atp500_firmware
- usg_flex_100
- usg1900
- usg20w-vpn
- usg60_firmware
- usg_flex_500_firmware
Insufficiently Protected Credentials