logo

Scores of Biometrics Bugs Emerge, Highlighting Authentication Risks

ID: 6ed1224e-3ddd-50c9-a8c8-885b6898fbf8

STIX ID: report--6ed1224e-3ddd-50c9-a8c8-885b6898fbf8

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

*Executive summary:* Kaspersky researchers found roughly two dozen vulnerabilities in ZKTeco biometric access terminals — including SQL injection, path traversal, input-validation flaws, and privileged command execution (notable examples CVE-2023-3938, CVE-2023-3939, CVE-2023-3940–3943) — that could allow attackers to extract biometric data and password hashes, modify device databases (e.g., add attacker faces), execute commands, and bypass physical access controls via manipulated QR codes; the devices are widely deployed in critical facilities which raises concern despite no confirmed active exploitation publicly reported. Recommended mitigations include isolating biometric readers on separate network segments, replacing default credentials, auditing device configurations, and protecting biometric stores with hardware-backed encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.