CVE-2026-8598
Awaiting Analysis
Awaiting Analysis - Queue
Unauthenticated Configuration Export in ZKTeco CCTV Cameras
Publication date: 2026-05-20
Last updated on: 2026-05-20
Assigner: ICS-CERT
Description
Description
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zkteco | ssc335-gc2063-face | to 5.0.1.2.20260421 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |