CVE-2020-29583 is a critical vulnerability affecting Zyxel USG devices, specifically firmware version 4.60, due to an undocumented "zyfwp" account with a hardcoded, unchangeable password accessible in cleartext within the firmware. This allows unauthenticated attackers to gain administrative access via SSH or the web interface. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 100/100, the vulnerability poses a severe risk, enabling full compromise of affected devices. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog and recent threat intelligence, with community discussion and media coverage highlighting its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.60CPE matchmatch criteria | cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60:*:*:*:*:*:*:* | ||
4.60CPE matchmatch criteria | cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.60:*:*:*:*:*:*:* | ||
4.60CPE matchmatch criteria | cpe:2.3:o:zyxel:usg40_firmware:4.60:*:*:*:*:*:*:* | ||
4.60CPE matchmatch criteria | cpe:2.3:o:zyxel:usg40w_firmware:4.60:*:*:*:*:*:*:* | ||
4.60CPE matchmatch criteria | cpe:2.3:o:zyxel:usg60_firmware:4.60:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.