CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If applicable, ensure attackers cannot reach the bundled Apache Tomcat manager application that is protected by hardcoded credentials (e.g., restrict access to the Tomcat manager/admin endpoints to trusted networks only via network controls/ACLs/firewall).
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20026?
CVE-2016-20026 is considered a high severity vulnerability due to the potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2016-20026?
To fix CVE-2016-20026, you should remove or replace the hardcoded credentials in the Apache Tomcat server configuration and ensure strong, unique credentials are implemented.
What type of vulnerability is CVE-2016-20026?
CVE-2016-20026 is a remote code execution vulnerability caused by hardcoded credentials in the ZKTeco ZKBioSecurity 3.0 application.
Who is affected by CVE-2016-20026?
Users and administrators of ZKTeco ZKBioSecurity 3.0 are affected by CVE-2016-20026 due to the presence of hardcoded credentials.
Can CVE-2016-20026 be exploited remotely?
Yes, CVE-2016-20026 can be exploited remotely by an attacker without authentication.