CVE-2022-42953: High severity zkteco zmm200 firmware vulnerability
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-42953.
Which ZKTeco products are affected by this vulnerability?
Certain ZKTeco products such as ZEM500-510-560-760, ZEM600-800, ZEM720, and ZMM are affected.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by making direct requests to the form/DataApp?style=1 and form/DataApp?style=0 URLs to access sensitive information.
What is the severity of CVE-2022-42953?
The severity of CVE-2022-42953 is high with a CVSS score of 7.5.
Are there any known fixes for this vulnerability?
Currently, there are no known fixes for this vulnerability. It is recommended to follow the vendor's security advisory for updates and mitigation measures.