logo

ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws

ID: ebdb510f-dd21-5f44-8eb2-0c61d2198186

STIX ID: report--ebdb510f-dd21-5f44-8eb2-0c61d2198186

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-14

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Kaspersky researchers reported 24 vulnerabilities in a ZKTeco biometric access system (firmware ZAM170-NF-1.8.25-7354-Ver1.0.0), including multiple high-severity issues (command injection, arbitrary file write/read, SQL injection, and stack-based buffer overflows) that could allow attackers to bypass authentication, steal biometric data, execute code as root, and deploy backdoors; recommended mitigations include network segmentation for biometric readers, strong admin passwords, minimizing QR code use, and keeping devices updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.