CISA Known Exploited Vulnerability

CVE-2020-29583

Zyxel · Multiple Products

Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

Date added
BOD 22-01 due date
CWE CWE-522
Ransomware Unknown

CISA description

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

Required action

Apply updates per vendor instructions.