This repository contains a Python CLI for decrypting passwords stored with Zyxel's proprietary $4$ scheme, commonly found in mfg-default.conf configuration files on Zyxel WAX650S devices and potentially other Zyxel products.
The $4$ scheme is used by Zyxel to store sensitive information, such as administrative passwords, in a reversible encrypted format rather than a one-way hash. Analysis of Zyxel firmware has revealed that this scheme utilizes AES-192-CBC encryption with a static key and Initialization Vector (IV) embedded within the zysh binary.
This tool was developed from public firmware-analysis research, then packaged here as a reusable CLI instead of a one-off hard-coded sample.
The encryption process involves:
-
Salt: An 8-byte ASCII salt is extracted from the
$4$string. - Plaintext Preparation: The plaintext password is combined with the salt and then padded or repeated to fill an 80-byte buffer.
- Encryption: AES-192-CBC is applied to the prepared plaintext using a static key and IV.
- Encoding: The resulting ciphertext is Base64 encoded.
| Parameter | Value |
|---|---|
| Algorithm | AES-192-CBC |
| Key (Hex) | 001200054A1F23FB1F060A14CD0D018F5AC0001306F0121C |
| IV (Hex) | 0006001C01F01FC0FFFFFFFFFFFFFFFF |
- Python 3.x
pycryptodomelibrary:pip install pycryptodome
The CLI accepts either:
- the full
$4$<salt>$<cipher>$value - an entire config line containing that
$4$...$...$fragment - the Base64 ciphertext alone, together with
--salt
python3 zyxel_decrypter.py '$4$WliGKvFQ$yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U$'python3 zyxel_decrypter.py 'username admin encrypted-password $4$WliGKvFQ$yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U$ user-type admin'python3 zyxel_decrypter.py 'yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U' --salt WliGKvFQpython3 zyxel_decrypter.py '$4$WliGKvFQ$yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U$' --rawThe CLI prints the extracted salt and recovered plaintext password. --raw adds the full decrypted buffer for validation work.
Given the config line:
username admin encrypted-password $4$WliGKvFQ$yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U$ user-type admin
Running:
python3 zyxel_decrypter.py 'username admin encrypted-password $4$WliGKvFQ$yMEH/WCnH1+NXuIUp0lzpUinIyEnrHFoRgesi6NdOFytmQg8lRfsVzUUjBGY+FiS4Up6KIgoP8OMEP0L3hRYSN2kpFTDIet31GoNwlM+S7U$ user-type admin' --rawwill yield:
Salt: WliGKvFQ
Decrypted (raw): b'WliGKvFQ1234\x00123412341234123412341234123412341234123412341234123412341234123'
Decrypted Password: 1234
This tool is provided for educational and research purposes only. Use it responsibly and in accordance with applicable laws and regulations. The author is not responsible for any misuse or damage caused by this tool.
[1] HN Security. Zyxel firmware extraction and password analysis. https://hnsecurity.it/blog/zyxel-firmware-extraction-and-password-analysis/