CVE-2016-20029 PUBLISHED

ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 15.03.2026

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor ZKTeco Inc.
Product ZKTeco ZKBioSecurity
Versions
  • Version 3.0.1.0_R_230 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Incorrect Default Permissions CWE