CVE-2025-54464
Cleartext Storage Vulnerability in ZKTeco WL20
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
13 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device.
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
ZKTeco Co · WL20 Biometric Attendance SystemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →