Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24558 | This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device. |
Solution
Upgrade ZKTeco WL20 Biometric Attendance System firmware to version ZLM31-FXO1-4.0.3. https://www.zkteco.com/en/Security_Bulletinsibs/20
Workaround
No workaround given by the vendor.
Wed, 13 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Aug 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device. | |
| Title | Cleartext Storage Vulnerability in ZKTeco WL20 | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2025-08-13T13:10:37.654Z
Reserved: 2025-07-22T08:56:34.298Z
Link: CVE-2025-54464
Updated: 2025-08-13T13:10:34.565Z
Status : Awaiting Analysis
Published: 2025-08-13T12:15:25.927
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-54464
No data.
OpenCVE Enrichment
No data.
EUVD