7.5
CVSSv3

CVE-2022-42953

Published: 25/12/2022 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be prior to 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zkteco zmm200 firmware

zkteco zmm210 firmware

zkteco zmm220 firmware

zkteco zem720 firmware

zkteco zem600 firmware

zkteco zem800 firmware

zkteco zem510 firmware

zkteco zem560 firmware

zkteco zem760 firmware

zkteco zem500 firmware

Exploits

ZKTeco ZEM500-510-560-760, ZEM600-800, ZEM720, and ZMM suffer from a missing authentication vulnerability Versions below 888 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 1500 (ZMM200-220-210) are potentially affected ...