/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: more than 100K Zyxel firewalls and VPN gateways have a hardcoded admin-level backdoor that can grant attackers root access to devices

The username and password (zyfwp/PrOw!aN_fXp) were visible in one of the Zyxel firmware binaries.  —  More than 100,000 Zyxel firewalls …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is at least the third time researchers have pulled an embedded credential or implant out of networking gear: Fortinet faced a hardcoded-password remote-access flaw in its firewall software disclosed in 2016, and Cisco spent late 2015 chasing a stealthy backdoor infecting routers across four countries. What distinguishes the Zyxel case is scale and visibility — the zyfwp username and password sit plainly in a public firmware binary, putting root access on more than 100,000 firewalls and VPN gateways within reach of anyone who downloads the image.

The disclosure also reads differently after the fact: the related coverage shows Zyxel zero-days later featured in the largest cyberattack against Danish critical infrastructure, which breached 22 companies — evidence that this device class is not just a perimeter appliance but a recurring entry point into national infrastructure.

First-order effects

  • Owners of the affected Zyxel firewalls and VPN gateways face immediate root-level exposure from a credential visible in the firmware binary itself, making every internet-facing unit a candidate target until patched.
  • Zyxel must ship firmware updates and credential rotation guidance at scale, while the chip shortage's longer router lead times mean some customers cannot simply swap hardware and must patch in place.

Second-order effects

  • Security teams auditing vendor firmware now have a template — extract binaries, grep for embedded credentials — that applies equally to the Fortinet and Cisco precedents, forcing other firewall makers to defend their own images against the same scrutiny.
  • Buyers of edge security gear gain leverage to demand firmware-audit rights and faster patch SLAs, shifting procurement criteria toward vendors who can prove what is compiled into their devices.

Third-order effects

  • If hardcoded credentials keep surfacing across vendors — Fortinet in 2016, Cisco in 2015, Zyxel in 2021 — the likely structural outcome is mandatory third-party firmware audits or regulatory baseline requirements for network equipment sold into critical infrastructure.
  • The Danish attack's use of Zyxel zero-days suggests edge devices will increasingly be treated as strategic attack surface, pulling firewall vendors into the same national-security scrutiny long applied to telecom equipment suppliers.

The trend: Network-edge appliances are shifting from commodity IT purchases to audited, regulated critical infrastructure components as embedded-credential disclosures accumulate across vendors.

Discussion

  • @sub8u Subrahmanyam Kvj on x
    Death to backdoors!🤦‍♂ ️🤦‍♂️ “More than 100,000 Zyxel firewalls, VPN gateways, and access point controllers contain a hardcoded admin-level backdoor account that can grant attackers root access to devices via either the SSH interface or the web admin panel.” https://www.zdnet.com…
  • @binitamshah Binni Shah on x
    Backdoor account discovered in more than 100,000 Zyxel firewalls, VPN gateways : https://www.eyecontrol.nl/... Patch release + Zyxel security advisory for hardcoded credential vulnerability : https://www.zyxel.com/...
  • @sans_isc Sans Isc on x
    Yikes. Totally missed this #zyxel backdoor. Worst part: some models will not be patched until April. @ZyxelNews https://www.eyecontrol.nl/...
  • @weldpond Chris Wysopal on x
    A good example of industry not learning from past failures. We were stringsing appliance firmware binaries 20 years ago and finding hard coded auth. https://www.zdnet.com/...
  • @artemr Artem Russakovskii on x
    What the fuck, Zyxel? The username and password (zyfwp/PrOw!aN_fXp) were visible in one of the Zyxel firmware binaries. Backdoor account discovered in more than 100,000 Zyxel firewalls, VPN gateways https://www.zdnet.com/...