ZKTeco ZKBioSecurity 3.0 Hardcoded...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary ZKBioSecurity3.0 is the ultimate "All in One" web based security platform developed by ZKTeco. It contains four integrated modules: access control, video linkage, elevator control and visitor management. With an optimized system architecture designed for high level biometric identification and a modern-user friendly UI, ZKBioSecurity 3.0 provides the most advanced solution for a whole new user experience. ### Description The ZKBioSecurity solution suffers from a use of hard-coded credentials. The application comes bundled with a pre-configured apache tomcat server and an exposed 'manager' application that after authenticating with the credentials: username: zkteco, password: zkt123, located in tomcat-users.xml file, it allows malicious WAR archive containing a JSP application to be uploaded, thus giving the attacker the ability to execute arbitrary code with SYSTEM privileges. ### Vendor ZKTeco Inc. - http://www.zkteco.com ### Affected Version * 3.0.1.0_R_230 *...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息