CVE-2025-55279
BaseFortify
Publication date: 2025-08-13
Last updated on: 2025-08-13
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zkteco | wl20 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in ZKTeco WL20 devices because a hard-coded private key is stored in plaintext within the device firmware. An attacker with physical access to the device can extract the firmware and analyze its binary data to retrieve this private key.
How can this vulnerability impact me? :
If exploited, an attacker could use the retrieved private key to decrypt sensitive data without authorization and perform Man-in-the-Middle (MitM) attacks on the targeted device, potentially compromising the confidentiality and integrity of communications and data.