EXPOSURES › CVE-2020-29583
CVE-2020-29583
HIGH ⌖ ON CISA KEV · EXPLOITEDZyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account.
Zyxel network hardware shipped with a hard-coded, unchangeable password for an undocumented account, allowing attackers to bypass authentication on deployed devices. DIB organizations must audit vendor hardware for default or hardcoded credentials and enforce strict change management to prevent unauthorized access and compliance violations.
Shame score — Shipping hardware with unchangeable hard-coded credentials is a negligent, avoidable failure that directly enables unauthorized access and violates basic security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
"Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ('zyfwp') with an unchangeable password."