CVE-2016-20029
Deferred
Deferred - Pending Action
File Path Manipulation in ZKTeco ZKBioSecurity 3.0 Enables Data Exposure
Publication date: 2026-03-16
Last updated on: 2026-06-08
Assigner: VulnCheck
Description
Description
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zkteco | zkbiosecurity | 3.0.1.0_r_230 |
| zkteco | zkbiosecurity | to 3.0.1.0_R_230 (inc) |
| zkteco | zkbiosecurity | 1.0.1.0_r_1916 |
| zkteco | zkbiosecurity | 6.0.1.0_r_1757 |
| zkteco | zkbiosecurity | 2.0.1.0_r_777 |
| zkteco | zkbiosecurity | 2.0.1.0_r_877 |
| zkteco | zkbiosecurity | 2.0.1.0_r_489 |
| zkteco | zkbiosecurity | 1.0.1.0_r_197 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |