Zyxel.Firewall.Default.Credentials

description-logoDescription

This indicates an attack attempt against a Security Bypass Vulnerability in Zyxel firewalls and AP controllers.
The vulnerability is due to hard-coded default credentials on the vulnerable devices. Successful exploitation can lead to accessing the target system with administrative privileges.

affected-products-logoAffected Products

ATP series running firmware ZLD V4.60
USG series running firmware ZLD V4.60
USG FLEX series running firmware ZLD V4.60
VPN series running firmware ZLD V4.60
NXC2500 running firmware V6.00 through V6.10
NXC5500 running firmware V6.00 through V6.10

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://www.zyxel.com/support/CVE-2020-29583.shtml

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2022-06-27 21.345 Default_action:pass:drop
2022-06-16 21.340