uOS 1.38-Hardening Admin Security: Disabling the Default Admin Account

Options
Zyxel_Lynn
Zyxel_Lynn Posts: 183 image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited May 20 in Other Topics

Securing Administrative Access: Disabling the Default Admin

To mitigate the risk of brute-force attacks, Zyxel now allows administrators to disable the default "admin" account on H series firewalls.

Safe Disabling and Safeguards

The default "admin" username is a frequent target for automated attackers. Administrators can now toggle this account to "Disabled" under User & Authentication settings. 

To prevent accidental lockout, the system requires that at least one other active administrator-level account exists before the default account can be disabled.


Emergency Recovery Mechanism

If access is lost, a hardware-level recovery is available. By entering debug mode during the boot process and executing the command: atkz -g, the firewall will re-enable the default admin account and reset its password to factory defaults while keeping all other startup configurations and user accounts intact.