CVE-2016-20029
MEDIUMZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
Title source: cnaDescription
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.
Exploits (1)
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
Zero Science Lab Disclosure
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5365.php
Vdb Entry vdb-entry
IBM X-Force Exchange
https://exchange.xforce.ibmcloud.com/vulnerabilities/116489
Third Party Advisory third-party-advisory
VulnCheck Advisory: ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-file-path-manipulation-vulnerability
Scores
CVSS v3
6.2
EPSS
0.0001
EPSS Percentile
1.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-276
Status
published
Products (1)
ZKTeco Inc./ZKTeco ZKBioSecurity
3.0.1.0_R_230
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026