Researchers: more than 100K Zyxel firewalls and VPN gateways have a hardcoded admin-level backdoor that can grant attackers root access to devices
The username and password (zyfwp/PrOw!aN_fXp) were visible in one of the Zyxel firmware binaries. — More than 100,000 Zyxel firewalls …
Context & Ripple Effects
This is at least the third time researchers have pulled an embedded credential or implant out of networking gear: Fortinet faced a hardcoded-password remote-access flaw in its firewall software disclosed in 2016, and Cisco spent late 2015 chasing a stealthy backdoor infecting routers across four countries. What distinguishes the Zyxel case is scale and visibility — the zyfwp username and password sit plainly in a public firmware binary, putting root access on more than 100,000 firewalls and VPN gateways within reach of anyone who downloads the image.
The disclosure also reads differently after the fact: the related coverage shows Zyxel zero-days later featured in the largest cyberattack against Danish critical infrastructure, which breached 22 companies — evidence that this device class is not just a perimeter appliance but a recurring entry point into national infrastructure.
First-order effects
- Owners of the affected Zyxel firewalls and VPN gateways face immediate root-level exposure from a credential visible in the firmware binary itself, making every internet-facing unit a candidate target until patched.
- Zyxel must ship firmware updates and credential rotation guidance at scale, while the chip shortage's longer router lead times mean some customers cannot simply swap hardware and must patch in place.
Second-order effects
- Security teams auditing vendor firmware now have a template — extract binaries, grep for embedded credentials — that applies equally to the Fortinet and Cisco precedents, forcing other firewall makers to defend their own images against the same scrutiny.
- Buyers of edge security gear gain leverage to demand firmware-audit rights and faster patch SLAs, shifting procurement criteria toward vendors who can prove what is compiled into their devices.
Third-order effects
- If hardcoded credentials keep surfacing across vendors — Fortinet in 2016, Cisco in 2015, Zyxel in 2021 — the likely structural outcome is mandatory third-party firmware audits or regulatory baseline requirements for network equipment sold into critical infrastructure.
- The Danish attack's use of Zyxel zero-days suggests edge devices will increasingly be treated as strategic attack surface, pulling firewall vendors into the same national-security scrutiny long applied to telecom equipment suppliers.
The trend: Network-edge appliances are shifting from commodity IT purchases to audited, regulated critical infrastructure components as embedded-credential disclosures accumulate across vendors.