ZKTeco ZKBioSecurity 3.0 Hardcoded...

- AV AC AU C I A
发布: 2016-08-31
修订: 2025-04-13

The ZKBioSecurity solution suffers from a use of hard-coded credentials. The application comes bundled with a pre-configured apache tomcat server and an exposed 'manager' application that after authenticating with the credentials: username: zkteco, password: zkt123, located in tomcat-users.xml file, it allows malicious WAR archive containing a JSP application to be uploaded, thus giving the attacker the ability to execute arbitrary code with SYSTEM privileges. Version 3.0.1.0_R_230 is affected.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息