Junglewise Threat Intelligence

CVE-2016-20026: ZKTeco ZKBioSecurity hardcoded credentials in bundled Apache Tomcat

CVE-2016-20026 · Severity: critical · CVSS 9.8 · Published 2026-03-16

Technologies: Zkteco ZKBioSecurity. Vendors: Zkteco.

Executive brief

ZKTeco ZKBioSecurity is an all-in-one security platform used for access control, video surveillance, and visitor management. A vulnerability in its bundled web server allows unauthenticated attackers to take full control of the system using known, preset login credentials. This could lead to unauthorized access to secure facilities, theft of sensitive biometric or visitor data, and complete disruption of security operations.

Technical details

ZKTeco ZKBioSecurity (up to version 3.0.1.0_R_230) bundles an Apache Tomcat server (version 7.0.56) with a pre-configured 'manager' application. The configuration file 'tomcat-users.xml' contains hardcoded credentials (username: 'zkteco', password: 'zkt123') with administrative roles including 'manager-gui' and 'manager-script'. An unauthenticated remote attacker can use these credentials to access the Tomcat Manager interface and deploy a malicious WAR archive containing a JSP webshell. Because the service typically runs with high privileges on Windows installations, this results in arbitrary code execution as 'nt authority\system'.

Affected products

  • ZKTeco ZKBioSecurity <= 3.0.1.0_R_230

Timeline

  • 2016-07-18: disclosed: Vulnerability discovered by Zero Science Lab
  • 2016-08-31: advisory: Public advisory and exploit released by Zero Science Lab and Exploit-DB
  • 2026-03-16: advisory: CVE-2016-20026 published to NVD

References

Related threats