ZKTeco ZKBioSecurity 3.0...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary ZKBioSecurity3.0 is the ultimate "All in One" web based security platform developed by ZKTeco. It contains four integrated modules: access control, video linkage, elevator control and visitor management. With an optimized system architecture designed for high level biometric identification and a modern-user friendly UI, ZKBioSecurity 3.0 provides the most advanced solution for a whole new user experience. ### Description The issue exist due to the way visLogin.jsp script processes the login request via the 'EnvironmentUtil.getClientIp(request)' method. It runs a check whether the request is coming from the local machine and sets the ip variable to '127.0.0.1' if equal to 0:0:0:0:0:0:0:1. The ip variable is then used as a username value with the password '123456' to authenticate and disclose sensitive information and/or do unauthorized actions. ### Vendor ZKTeco Inc. - http://www.zkteco.com ### Affected Version * 3.0.1.0_R_230 * Platform: 3.0.1.0_R_230 * Personnel:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息