Description
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Published: 2022-12-25
Score: 7.5 High
EPSS: 10.9% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-46008 Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
History

Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Zkteco Zem500 Zem500 Firmware Zem510 Zem510 Firmware Zem560 Zem560 Firmware Zem600 Zem600 Firmware Zem720 Zem720 Firmware Zem760 Zem760 Firmware Zem800 Zem800 Firmware Zmm200 Zmm200 Firmware Zmm210 Zmm210 Firmware Zmm220 Zmm220 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-15T13:33:43.485Z

Reserved: 2022-10-15T00:00:00.000Z

Link: CVE-2022-42953

cve-icon Vulnrichment

Updated: 2024-08-03T13:19:05.508Z

cve-icon NVD

Status : Modified

Published: 2022-12-25T05:15:10.433

Modified: 2025-04-15T14:15:33.560

Link: CVE-2022-42953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses