CVE-2025-45746
- EPSS 0.28%
- Published 13.05.2025 00:00:00
- Last modified 21.05.2025 14:15:31
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically on...
CVE-2024-36526
- EPSS 0.32%
- Published 09.07.2024 17:15:19
- Last modified 17.06.2025 19:06:01
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
CVE-2024-35433
- EPSS 0.1%
- Published 30.05.2024 18:15:09
- Last modified 17.06.2025 19:17:28
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.
CVE-2024-35428
- EPSS 0.79%
- Published 30.05.2024 17:15:34
- Last modified 13.03.2025 15:15:44
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.
CVE-2024-35429
- EPSS 0.26%
- Published 30.05.2024 17:15:34
- Last modified 21.11.2024 09:20:19
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
CVE-2024-35431
- EPSS 2.21%
- Published 30.05.2024 17:15:34
- Last modified 17.06.2025 19:17:36
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
CVE-2024-35430
- EPSS 0.07%
- Published 30.05.2024 16:15:10
- Last modified 09.07.2025 17:15:30
In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.
CVE-2024-35432
- EPSS 0.17%
- Published 30.05.2024 16:15:10
- Last modified 17.06.2025 19:36:41
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.