Zyxel is a well-known brand in firewalls, VPNs, access controllers and other products, and is loved by many companies and enterprises. Recently, the Dutch security research team Eye Control discovered the so-called “worst vulnerability” in many of its flagship series, and recommended that many users update their systems as soon as possible to avoid intrusions and threats from unscrupulous people.

Zyxel reports hard coding vulnerability, most major series are affected (supplementary 1/4 official news)
According to the CVE-2020-29583 vulnerability reported by security researchers, it is estimated that a hardcoded account is built into more than 100,000 Zyxel firewalls, VPN gateways, and access controllers, which can allow attackers to gain root-level access to the device through the SSH interface or web administrator control panel. Security personnel warn that because many of these devices are used for side-support on corporate networks, anyone from DDoS botnet operators to state-backed hacker organizations and extortion groups can abuse the backdoor to access corporate devices and in turn attack internal networks if they know this account.

The affected series cover most flagship products, including the following series:
【To download the update for all affected models, click here】
-
Advanced Threat Protection (ATP) series: mainly used for firewalls
-
Unified Security Gateway (USG) series: mainly used for hybrid firewalls or VPN gateways
-
USG FLEX series: mainly used for hybrid firewalls or VPN gateways
-
VPN series: mainly used for VPN gateways
-
NXC series: mainly used for WLAN access point control
According to Zyxel, fix updates for the APT, USG, USG Flex and VPN series have been released, while fixes for the NXC series are expected to be launched in April 2021. Eye Control says that an account with the username “zyfwp” that has root permissions on the device can be deleted after installing the update.

◎Data source:Eye Control、ZDnet
2021/01/04 updated
According to official confirmation, although the account password is hard-coded in the firmware, it only exists in the previous version and is only used for automatic login reading during firmware updates. Writing work cannot be performed. The account will be completely removed after the update. According to actual statistics, there are only 122 affected devices in Taiwan, and the number of affected devices announced by Eye Control is an estimate. The original Zyxel manufacturer has stepped up its work and will release NXC series updates as quickly as possible in 1/8 for download and repair.
【Zyxel Security Notice, please refer to this link】
Source: KOCPC Chinese