- Description
- Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Data from CISA
- Vulnerability name
- Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- May 3, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "660A9038-66FB-4F71-BA50-8ED69C2E2274"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg20-vpn:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7239C54F-EC9E-44B4-AE33-1D36E5448219"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E892C61D-80DE-4FA4-9224-1B3C72A31F57"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg20w-vpn:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "06D2AD3A-9197-487D-A267-24DE332CC66B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg40_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29398F33-D8B4-432D-A075-4454DA1B23F0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg40:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5CCD2777-CC85-4BAA-B16B-19C2DB8DB742"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg40w_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA146A61-7B27-4E48-87C1-A82F45FB692A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg40w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0906F3FA-793B-421D-B957-7E9C18C1AEC0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg60_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14F685CA-FBD9-4A00-BB23-BF914DFE41D9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "26900300-1325-4C8A-BC3B-A10233B2462A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg60w_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "022CF987-20A8-4450-A8B8-94AF2F2D453E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg60w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A5A7555E-BC29-460C-A701-7DCDEAFE67F3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg110_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7540894B-A1EF-40C3-ABD3-D58CDB45622F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg110:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4834AC5E-884D-4A1C-A39B-B3F4A281E3CB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg210_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6556E988-676D-4E7A-BDC2-A53256548FEA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg210:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EAFF1122-755A-4531-AA2E-FD6E8478F92F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg310_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56EF63D0-63DD-4EFD-AE7A-5680710AE573"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg310:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F302801D-3720-4598-8458-A8938BD6CB46"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg1100_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8451A4C8-2023-41A4-81A9-91565CEC6918"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg1100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B68C4BD-3279-47AB-AC2A-7555163B12E2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg1900_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7391C72E-CAB3-4FAD-9FB6-789F48516C26"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg1900:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "60F4E816-C4D3-451A-965C-45387D7DEB5B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg2200_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3B7B49D-7DB2-4D44-AC55-6B1F828B512D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg2200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "231547C3-33B8-42B7-983E-AA3C6CA5D107"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:zywall110_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52922CA2-1C1E-4972-A52E-D9FA84BCC4C1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:zywall110:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2347F91E-8AA3-4EB5-AD7F-7602A46C20BD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:zywall310_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9336382-E759-4869-9B59-57366E176CA2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:zywall310:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3A97613C-26EF-481E-9215-197FE7A9D1C6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:zywall1100_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "271DE232-FAED-48A1-891C-33A6FDBA9EAA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:zywall1100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "53A5732E-193B-4017-A434-A76BE80E20D9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp100_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7DC9FE97-6B7D-41E8-879C-572B23CB1105"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7F7654A1-3806-41C7-82D4-46B0CD7EE53B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp100w_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61489A79-AAF5-4347-9E10-73F139D30EE2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "47398FD0-6C5E-4625-9EFD-DE08C9AB7DB2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp200_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB876002-669D-4052-B1B0-DA8F0B4EC500"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D68A36FF-8CAF-401C-9F18-94F3A2405CF4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp500_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E6231DF-ADB3-43A9-AC3B-C72905584B05"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2818E8AC-FFEE-4DF9-BF3F-C75166C0E851"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp700_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEDC5E3D-2103-4545-8611-B1C49B4B5BAB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0B41F437-855B-4490-8011-DF59887BE6D5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:atp800_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "246B2EF8-6412-4E69-91A5-B394BF4D299F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "66B99746-0589-46E6-9CBD-F38619AD97DC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:vpn50_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6A568BA-58D3-400C-9742-8E966C90D83E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:vpn50:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9E3AC823-0ECA-42D8-8312-2FBE5914E4C0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:vpn100_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65E48F65-A408-4A93-BBBC-44D5054D9841"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:vpn100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "81D90A7B-174F-40A1-8AF4-08B15B7BAC40"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:vpn300_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B2E5F78-7F7B-46BA-A7B1-0A49F4A6509D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:vpn300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3C45C303-1A95-4245-B242-3AB9B9106CD4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:vpn1000_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E39AE158-E577-403B-867E-CCD5F8EE5FC5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:vpn1000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EECD311A-4E96-4576-AADF-47291EDE3559"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_flex_100_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14484416-6575-4E23-96A7-F37936F75BAB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2B30A4C0-9928-46AD-9210-C25656FB43FB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_flex_100w_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0597006-8FA7-4622-9C13-AFE9767CADE5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D74ABA7E-AA78-4A13-A64E-C44021591B42"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_flex_200_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28D39C78-DD5A-47FB-9590-B79AABA1038B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F93B6A06-2951-46D2-A7E1-103D7318D612"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_flex_500_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "438B93F0-7CBF-49E9-B556-CFEFE2E6EED0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "92C697A5-D1D3-4FF0-9C43-D27B18181958"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_flex_700_firmware:4.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "414BCC73-277B-48FD-8273-B33A780806D0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9D1396E3-731B-4D05-A3F8-F3ABB80D5C29"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]