logo

Critical ZKTeco CCTV Flaw (CVE-2026-8598) Leaks Admin Credentials Without Authentication

ID: 6939f9fc-e046-5315-8687-b51ea83fb2d6

STIX ID: report--6939f9fc-e046-5315-8687-b51ea83fb2d6

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

This advisory describes CVE-2026-8598, a critical (CVSS 9.1) flaw in ZKTeco SSC335-GC2063-Face-0b77 cameras where an undocumented, unauthenticated configuration export port discloses device configuration and administrative credentials, enabling remote takeover; vendor patch V5.0.1.2.20260421 and network segmentation are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.