← KEV catalog
CISA known exploited vulnerability

CVE-2020-29583

Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

SOURCE FACT

Zyxel · Multiple Products

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-29583

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?