CVE-2016-20026
CRITICALZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
Title source: cnaDescription
ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.
Exploits (1)
References (6)
Scores
CVSS v3
9.8
EPSS
0.0007
EPSS Percentile
21.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
ZKTeco Inc./ZKTeco ZKBioSecurity
3.0.1.0_R_230
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026