Researchers found secret backdoor account in several Zyxel Firewall, VPN Products


Researchers found secret backdoor account in several Zyxel Firewall, VPN Products: Zyxel has released a patch to address a critical vulnerability in its firmware concerning a hardcoded, undocumented secret account that could be abused by an attacker to login with administrative privileges and compromise its networking devices.

 

The flaw, tracked as CVE-2020-29583 (CVSS score 7.8), affects version 4.60 present in a wide-range of Zyxel devices, including Unified Security Gateway (USG), USG FLEX, ATP, and VPN firewall products.

 

According to the advisory published by Zyxel, the undocumented account ("zyfwp") comes with an unchangeable password ("PrOw!aN_fXp") that's not only stored in plaintext but could also be used by a malicious third-party to login to the SSH server or web interface with admin privileges.

 

Zyxel said the hardcoded credentials were put in place to deliver automatic firmware updates to connected access points through FTP.

 

Noting that around 10% of 1000 devices in the Netherlands run the affected firmware version, Teusink said the flaw's relative ease of exploitation makes it a critical vulnerability. 


Read More

Comments

Popular posts from this blog

N Chandrasekaran appointed chairman of Tata Sons

DoT Secretary hints at making Draft NTP 2018 available in public domain soon

Visa buys NFT based CryptoPunk and paid $150,000 in Etherium