Skip to content

Conversation

@h00die
Copy link
Contributor

@h00die h00die commented Jan 18, 2021

This PR adds the hardcoded creds found in Zyxel devices which is captured as cve-2020-29583 to the unix creds files. Nice and easy PR.

@adfoster-r7 adfoster-r7 merged commit 8027ae1 into rapid7:master Jan 19, 2021
@adfoster-r7 adfoster-r7 added the rn-enhancement release notes enhancement label Jan 19, 2021
@adfoster-r7
Copy link
Contributor

adfoster-r7 commented Jan 19, 2021

Release Notes

Added hardcoded credentials found in Zyxel devices to the unix creds files (CVE-2020-29583).

@wvu
Copy link
Contributor

wvu commented Jan 19, 2021

At the very least, the project could benefit from default-cred "userpass" lists instead of splitting known cred pairs across files. cc @zeroSteiner

@h00die
Copy link
Contributor Author

h00die commented Jan 19, 2021

A very valid point, forgot about that file tbh

@h00die h00die deleted the zyxel branch February 5, 2021 22:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rn-enhancement release notes enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants