CyberSec.Space Logo
Back to CVE Browser

CVE-2020-29583

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score96.7360%
EPSS Percentile95.75th
Published2020-12-22
Last Modified2025-11-07
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Affected Platforms (CPE)

πŸ’»
Zyxel

Usg20 Vpn Firmware

= 4.60
πŸ’»
Zyxel

Usg20w Vpn Firmware

= 4.60
πŸ’»
Zyxel

Usg40 Firmware

= 4.60
πŸ’»
Zyxel

Usg40w Firmware

= 4.60

References & Advisories

Related Vulnerabilities