Skip to content
COOEY

EXPOSURES › CVE-2020-29583

CVE-2020-29583

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-29583 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildhardcoded-credsunpatched

Zyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account.

Zyxel network hardware shipped with a hard-coded, unchangeable password for an undocumented account, allowing attackers to bypass authentication on deployed devices. DIB organizations must audit vendor hardware for default or hardcoded credentials and enforce strict change management to prevent unauthorized access and compliance violations.

Shame score — Shipping hardware with unchangeable hard-coded credentials is a negligent, avoidable failure that directly enables unauthorized access and violates basic security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Zyxel's hard-coded credentials flaw is widely recognized as a severe, unchangeable vulnerability that left devices exposed to unauthorized access, reflecting poorly on the vendor's security posture an
cooey ↗ severe-fallout -0.80
NVD entry confirms the flaw's severity and the unchangeable nature of the password, indicating a critical failure in vendor security design.
"Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ('zyfwp') with an unchangeable password."
NIST ↗ severe-fallout +0.00
No direct commentary on Zyxel's handling; purely a government website homepage.
Dark Reading ↗ severe-fallout +0.00
No direct commentary on Zyxel's handling; purely a news site homepage.
cybersecuritynews.com ↗ severe-fallout +0.00
No direct commentary on Zyxel's handling; unrelated article about AI agents.
www.cvefind.com ↗ severe-fallout +0.00
No direct commentary on Zyxel's handling; purely a database listing.
cvefeed.io ↗ severe-fallout +0.00
No direct commentary on Zyxel's handling; purely a CISA KEV catalog page.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.