CVE-2026-8598
Deferred
Deferred - Pending Action
Unauthenticated Configuration Export in ZKTeco CCTV Cameras
Vulnerability report for CVE-2026-8598, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-05-20
Last updated on: 2026-06-16
Assigner: ICS-CERT
Description
Description
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zkteco | ssc335-gc2063-face | to 5.0.1.2.20260421 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |