CVE-2020-29583-Zyxel security advisory for hardcoded credential vulnerability
by CIRT Team
DESCRIPTION
Zyxel has released a patch for the hardcoded credential vulnerability of firewalls and AP controllers recently reported by researchers from Eye Control Netherlands. Users are advised to install the applicable firmware updates for optimal protection.
A hardcoded credential vulnerability was identified in the “zyfwp” user account in some Zyxel firewalls and AP controllers. The account was designed to deliver automatic firmware updates to connected access points through FTP.
IMPACT
As the zyfwp user has admin privileges, an attacker could completely compromise the confidentiality, integrity and availability of the device.
SYSTEM AFFECTED
Full list available on below URL:
https://www.zyxel.com/support/CVE-2020-29583.shtml
RECOMMENDATIONS
Should update to the latest firmware as per vendor advisory.
REFERENCES
- https://www.zyxel.com/support/CVE-2020-29583.shtml
- https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts