Executive brief
ZKTeco ZKBioSecurity is an all-in-one security platform used for access control, video surveillance, and visitor management. A vulnerability in its bundled web server allows unauthenticated attackers to take full control of the system using known, preset login credentials. This could lead to unauthorized access to secure facilities, theft of sensitive biometric or visitor data, and complete disruption of security operations.
Technical details
ZKTeco ZKBioSecurity (up to version 3.0.1.0_R_230) bundles an Apache Tomcat server (version 7.0.56) with a pre-configured 'manager' application. The configuration file 'tomcat-users.xml' contains hardcoded credentials (username: 'zkteco', password: 'zkt123') with administrative roles including 'manager-gui' and 'manager-script'. An unauthenticated remote attacker can use these credentials to access the Tomcat Manager interface and deploy a malicious WAR archive containing a JSP webshell. Because the service typically runs with high privileges on Windows installations, this results in arbitrary code execution as 'nt authority\system'.
Affected products
- ZKTeco ZKBioSecurity <= 3.0.1.0_R_230
Timeline
- 2016-07-18: disclosed: Vulnerability discovered by Zero Science Lab
- 2016-08-31: advisory: Public advisory and exploit released by Zero Science Lab and Exploit-DB
- 2026-03-16: advisory: CVE-2016-20026 published to NVD
References
- https://cxsecurity.com/issue/WLB-2016080266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/116484
- https://packetstormsecurity.com/files/138567
- https://www.exploit-db.com/exploits/40324/
- https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-hardcoded-credentials-remote-code-execution
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5362.php