Taiwanese vendor Zyxel has addressed a critical vulnerability in its firmware related to the presence of a hardcoded undocumented secret account. The vulnerability, tracked as CVE-2020-29583, is tracked as a critical flaw. The vendor removed all vulnerable firmware versions from its cloud and website, except for USG FLEX 100W/700 due to base FW upgrade. Around 10% of 1000 devices in the Netherlands run a vulnerable version of the firmware version. Vulnerability was discovered by the security researcher Niels Teusink from EYE.”]
Source: https://securityaffairs.co/wordpress/112877/iot/secret-backdoor-zyxel-devices.html