CVE-2026-8598 PUBLISHED

Unauthenticated Export Service in ZKTeco CCTV Cameras

Assigner: icscert
Reserved: 14.05.2026 Published: 20.05.2026 Updated: 20.05.2026

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.1

Product Status

Vendor ZKTeco
Product SSC335-GC2063-Face-0b77 Solution Camera
Versions Default: unaffected
  • affected from 0 to V5.0.1.2.20260421 (excl.)
  • Version V5.0.1.2.20260421 is unaffected

Solutions

Please see the security advisory from ZKTeco here: https://www.zkteco.com/en/announcement/23 for further information. https://www.zkteco.com/en/announcement/23

Credits

  • Souvik Kandar reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-288 CWE