Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products
Zyxel has released a patch to handle a crucial vulnerability in its firmware regarding a hardcoded undocumented key account that could be abused by an attacker to login with administrative privileges and compromise its networking gadgets.
The flaw, tracked as CVE-2020-29583 (CVSS score 7.8), affects version 4.60 present in huge-array of Zyxel devices, such as Unified Protection Gateway (