CVE-2022-42953
25.12.2022, 05:15
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Vendor | Product | Version |
---|---|---|
zkteco | zmm200_firmware | 𝑥 < 15.00 |
zkteco | zmm210_firmware | 𝑥 < 15.00 |
zkteco | zmm220_firmware | 𝑥 < 15.00 |
zkteco | zem720_firmware | 𝑥 < 8.88 |
zkteco | zem600_firmware | 𝑥 < 8.88 |
zkteco | zem800_firmware | 𝑥 < 8.88 |
zkteco | zem510_firmware | 𝑥 < 8.88 |
zkteco | zem560_firmware | 𝑥 < 8.88 |
zkteco | zem760_firmware | 𝑥 < 8.88 |
zkteco | zem500_firmware | 𝑥 < 8.88 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration