CVE-2025-54464
Cleartext Storage Vulnerability in ZKTeco WL20
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
13 ago 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device.
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
ZKTeco Co · WL20 Biometric Attendance System¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →