CVE-2025-54464: Cleartext Storage Vulnerability in ZKTeco WL20
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54464?
The severity of CVE-2025-54464 is considered high due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-54464?
To fix CVE-2025-54464, ensure that the firmware is updated to a version that protects admin and user credentials using encryption.
Who is affected by CVE-2025-54464?
Devices running ZKTeco WL20 firmware are affected by CVE-2025-54464.
Can CVE-2025-54464 be exploited remotely?
CVE-2025-54464 requires physical access to the device, making remote exploitation unlikely.
What are the risks associated with CVE-2025-54464?
The risks include potential unauthorized access to administrative and user credentials stored in plain text.