CVE-2022-42953
HIGH EXPLOITEDZKTeco <8.88 - Info Disclosure
Title source: llmDescription
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Exploits (1)
exploitdb
WRITEUP
by RedTeam Pentesting GmbH · textwebappsjsp
https://www.exploit-db.com/exploits/51112
Scores
CVSS v3
7.5
EPSS
0.1088
EPSS Percentile
93.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2024-01-06
CWE
CWE-425
Status
published
Products (10)
zkteco/zem500_firmware
< 8.88
zkteco/zem510_firmware
< 8.88
zkteco/zem560_firmware
< 8.88
zkteco/zem600_firmware
< 8.88
zkteco/zem720_firmware
< 8.88
zkteco/zem760_firmware
< 8.88
zkteco/zem800_firmware
< 8.88
zkteco/zmm200_firmware
< 15.00
zkteco/zmm210_firmware
< 15.00
zkteco/zmm220_firmware
< 15.00
Published
Dec 25, 2022
Tracked Since
Feb 18, 2026