CVE-2025-54464
BaseFortify
Publication date: 2025-08-13
Last updated on: 2025-08-13
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zkteco | wl20 | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in ZKTeco WL20 devices because the admin and user credentials are stored in the device firmware without encryption. An attacker who has physical access to the device can extract the firmware and reverse engineer it to obtain these unencrypted credentials.
How can this vulnerability impact me? :
If exploited, an attacker with physical access could gain unauthorized access to the device by retrieving the stored admin and user credentials. This could lead to unauthorized control or manipulation of the device and potentially compromise the security of systems relying on it.