Blog | G5 Cyber Security

Expert found a secret backdoor in Zyxel firewall and VPN

Taiwanese vendor Zyxel has addressed a critical vulnerability in its firmware related to the presence of a hardcoded undocumented secret account. The vulnerability, tracked as CVE-2020-29583, is tracked as a critical flaw. The vendor removed all vulnerable firmware versions from its cloud and website, except for USG FLEX 100W/700 due to base FW upgrade. Around 10% of 1000 devices in the Netherlands run a vulnerable version of the firmware version. Vulnerability was discovered by the security researcher Niels Teusink from EYE.”]

Source: https://securityaffairs.co/wordpress/112877/iot/secret-backdoor-zyxel-devices.html

Exit mobile version