PoC Index

CVE-2020-29583

KEVHIGH 10.0EPSS 90.2%

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
90.16% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2021-11-03
Nuclei
critical · CWE-522
Published
2020-12-22
Updated
2025-10-21

Nuclei templates (1)

Exploit collections (1)

References

Related