Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Project Subscriptions

Vendors Products
Zem500 Firmware Subscribe
Zem510 Firmware Subscribe
Zem560 Firmware Subscribe
Zem600 Firmware Subscribe
Zem720 Firmware Subscribe
Zem760 Firmware Subscribe
Zem800 Firmware Subscribe
Zmm200 Firmware Subscribe
Zmm210 Firmware Subscribe
Zmm220 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-46008 Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-15T13:33:43.485Z

Reserved: 2022-10-15T00:00:00.000Z

Link: CVE-2022-42953

cve-icon Vulnrichment

Updated: 2024-08-03T13:19:05.508Z

cve-icon NVD

Status : Modified

Published: 2022-12-25T05:15:10.433

Modified: 2025-04-15T14:15:33.560

Link: CVE-2022-42953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses