logo

QR code SQL injection and other vulnerabilities in a popular biometric terminal

ID: a2d0d836-6acb-5076-8855-aafce6b8ad77

STIX ID: report--a2d0d836-6acb-5076-8855-aafce6b8ad77

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-06-11

Date Updated: 2026-04-29

Author: Georgy Kiguradze

...
...

This report documents a security analysis of a ZKTeco hybrid biometric terminal, describing firmware extraction and reverse engineering, network/protocol weaknesses (including a weak COMKey auth and reversible MAC), multiple insecure service handlers on port 4370/TCP and pushcomm, QR-code and SQL injection issues, buffer overflows enabling RCE, and arbitrary file read/write and command injection flaws; the authors assigned CVEs and published PoCs showing how these issues can lead to device compromise and physical access bypass.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.