QR code SQL injection and other vulnerabilities in a popular biometric terminal
ID: a2d0d836-6acb-5076-8855-aafce6b8ad77
STIX ID: report--a2d0d836-6acb-5076-8855-aafce6b8ad77
Feed Name: Securelist by Kaspersky
This report documents a security analysis of a ZKTeco hybrid biometric terminal, describing firmware extraction and reverse engineering, network/protocol weaknesses (including a weak COMKey auth and reversible MAC), multiple insecure service handlers on port 4370/TCP and pushcomm, QR-code and SQL injection issues, buffer overflows enabling RCE, and arbitrary file read/write and command injection flaws; the authors assigned CVEs and published PoCs showing how these issues can lead to device compromise and physical access bypass.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
