📦 Zkbio Cvsecurity

by Zkteco

🔍 What is Zkbio Cvsecurity?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-36526

CRITICAL CVSS 9.8 Jul 9, 2024

ZKTeco ZKBio CVSecurity v6.1.1 contains a hardcoded cryptographic key (CWE-259), allowing attackers to decrypt sensitive data or bypass authentication. This affects all installations of version 6.1.1....

CVE-2024-35428

HIGH CVSS 7.1 May 30, 2024

ZKTeco ZKBio CVSecurity 6.1.1 has a directory traversal vulnerability in the BaseMediaFile component that allows authenticated users to delete arbitrary files on the server. This can lead to denial of...

CVE-2024-35431

HIGH CVSS 7.5 May 30, 2024

ZKTeco ZKBio CVSecurity versions up to 6.4.1 are vulnerable to directory traversal via the photoBase64 parameter, allowing unauthenticated attackers to download arbitrary files from the server. This a...

CVE-2024-35430

HIGH CVSS 8.1 May 30, 2024

This vulnerability allows authenticated users in ZKTeco ZKBio CVSecurity to bypass password verification when exporting data. Attackers with valid credentials can extract sensitive information without...

CVE-2025-45746

MEDIUM CVSS 6.5 May 13, 2025

CVE-2025-45746 allows unauthenticated attackers to craft valid JWT tokens using a hardcoded secret, enabling authentication bypass to the ZKT ZKBio CVSecurity service console. This affects organizatio...