CVE-2022-42953

HIGH EXPLOITED

ZKTeco <8.88 - Info Disclosure

Title source: llm

Description

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Exploits (1)

exploitdb WRITEUP
by RedTeam Pentesting GmbH · textwebappsjsp
https://www.exploit-db.com/exploits/51112

Scores

CVSS v3 7.5
EPSS 0.1088
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2024-01-06
CWE
CWE-425
Status published
Products (10)
zkteco/zem500_firmware < 8.88
zkteco/zem510_firmware < 8.88
zkteco/zem560_firmware < 8.88
zkteco/zem600_firmware < 8.88
zkteco/zem720_firmware < 8.88
zkteco/zem760_firmware < 8.88
zkteco/zem800_firmware < 8.88
zkteco/zmm200_firmware < 15.00
zkteco/zmm210_firmware < 15.00
zkteco/zmm220_firmware < 15.00
Published Dec 25, 2022
Tracked Since Feb 18, 2026