← back
CVE-2022-42953highobserved exploitationCWE-425

CVE-2022-42953

63Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 7.5epss 4.8%
from disclosure to weapon93 days
Published on NVDDec 25
1st PoC+93d
VulnCheck+377d
exploitation probability
4.8%top 9% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short

ZKTeco time clock devices expose sensitive information through specific web URLs that don't require proper authentication. An attacker can directly access these URLs to retrieve confidential data without logging in.

Technical detail

CWE-425 (Direct Request) vulnerability in ZKTeco biometric devices allows unauthenticated access to sensitive information via form/DataApp endpoints with style parameters. The attack requires network access to the affected device's web interface; successful exploitation retrieves confidential data without authentication.

Summary generated and translated by AI from the official description.
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.