LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-29583: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-29583 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

CVE-2020-29583 is a hard-coded credentials flaw affecting certain Zyxel firewalls (ATP, USG, VM series) and AP controllers (NXC2500 and NXC5500). An undocumented account named "zyfwp" ships with a fixed, unchangeable password, giving anyone who knows or discovers those credentials a ready path into the device. For IT and security teams this matters because these products often sit at network perimeters or manage wireless infrastructure; unauthorized access can lead to configuration changes, traffic interception, or lateral movement. Confirm exact product coverage and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-522 (insufficiently protected credentials). The devices contain a built-in administrative account that is not documented for normal use and whose password cannot be altered by the operator. An attacker who obtains the credential—through public disclosure, reverse engineering, or prior compromise—can authenticate directly to the management interface or other services that accept that account. Because the password is static and shared across affected units, successful authentication does not require brute-forcing or credential stuffing against unique user accounts. Once inside, the attacker inherits the privileges associated with that account, which on network security appliances typically include the ability to alter rules, view logs, or pivot further into the environment. No additional exploit code is required beyond valid login; the vulnerability is the credential itself.

Am I affected? How to find it in your systems

These Zyxel firewalls and AP controllers commonly appear at Internet edges, in branch offices, or as wireless LAN controllers. Inventory steps:

If your environment uses centralized SIEM or firewall logging, create a simple detection rule for that username. Absence of the account name in logs does not prove the device is clean—only that the account has not yet been used.

How to remediate

The primary remediation is to apply the vendor-supplied updates exactly as described in the Zyxel security advisory for CVE-2020-29583. CISA’s required action is the same: follow the vendor’s instructions. After patching:

Document the firmware versions now running and schedule periodic checks against future Zyxel advisories.

If you can't patch immediately

When immediate firmware updates are operationally impossible, apply compensating controls to reduce exposure:

These measures do not remove the hard-coded credential; they only shrink the attack surface until the official update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities on perimeter devices can lead to broader network compromise and data exposure. If you have evidence of successful “zyfwp” logins or unexplained configuration changes, treat the incident as a potential breach: isolate affected systems, preserve logs, and begin incident-response procedures. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · Multiple Products
WeaknessCWE-522
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities