Description
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35334 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:* |
Thu, 15 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1. |
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zkteco
Zkteco zkbio Cvsecurity |
|
| CPEs | cpe:2.3:a:zkteco:zkbio_cvsecurity:6.11:*:*:*:*:*:*:* | |
| Vendors & Products |
Zkteco
Zkteco zkbio Cvsecurity |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-15T21:17:59.787Z
Reserved: 2024-05-17T00:00:00.000Z
Link: CVE-2024-35431
Updated: 2024-08-02T03:14:53.145Z
Status : Analyzed
Published: 2024-05-30T17:15:34.277
Modified: 2025-06-17T19:17:36.790
Link: CVE-2024-35431
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD