ZKTeco ZKBioSecurity 3.0 User...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary ZKBioSecurity3.0 is the ultimate "All in One" web based security platform developed by ZKTeco. It contains four integrated modules: access control, video linkage, elevator control and visitor management. With an optimized system architecture designed for high level biometric identification and a modern-user friendly UI, ZKBioSecurity 3.0 provides the most advanced solution for a whole new user experience. ### Description The weakness is caused due to the 'authLoginAction!login.do' script enumerating the list of valid usernames when some characters are provided via the 'username' parameter. ### Vendor ZKTeco Inc. - http://www.zkteco.com ### Affected Version * 3.0.1.0_R_230 * Platform: 3.0.1.0_R_230 * Personnel: 1.0.1.0_R_1916 * Access: 6.0.1.0_R_1757 * Elevator: 2.0.1.0_R_777 * Visitor: 2.0.1.0_R_877 * Video:2.0.1.0_R_489 * Adms: 1.0.1.0_R_197 ### Tested On * Microsoft Windows 7 Ultimate SP1 (EN) * Microsoft Windows 7 Professional SP1 (EN) * Apache-Coyote/1.1 * Apache...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息