CVE-2016-20029

MEDIUM

ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20029. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates a file path manipulation vulnerability in ZKTeco ZKBioSecurity 3.0, allowing an attacker to access sensitive files (e.g., web.xml) by traversing directories via a crafted URL. The PoC provides a direct example of the vulnerable endpoint and payload.

Description

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsjsp
https://www.exploit-db.com/exploits/40326

The exploit demonstrates a file path manipulation vulnerability in ZKTeco ZKBioSecurity 3.0, allowing an attacker to access sensitive files (e.g., web.xml) by traversing directories via a crafted URL. The PoC provides a direct example of the vulnerable endpoint and payload.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ZKTeco ZKBioSecurity 3.0 (versions 3.0.1.0_R_230 and related modules)
No auth needed
Prerequisites: network access to the target server
devstral-2 · analyzed Mar 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory
Zero Science Lab Disclosure
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5365.php
Third Party Advisory third-party-advisory
CXSecurity
https://cxsecurity.com/issue/WLB-2016090001
Vdb Entry vdb-entry
IBM X-Force Exchange
https://exchange.xforce.ibmcloud.com/vulnerabilities/116489
Exploit exploit
Packet Storm Security
https://packetstormsecurity.com/files/138570
Exploit exploit
Reference
https://www.exploit-db.com/exploits/40326/
Third Party Advisory third-party-advisory
VulnCheck Advisory: ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-file-path-manipulation-vulnerability

Scores

CVSS v3 6.2
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (1)
ZKTeco Inc./ZKTeco ZKBioSecurity 3.0.1.0_R_230
Published Mar 16, 2026
Tracked Since Mar 16, 2026