Executive brief
ZKTeco ZKBioSecurity is an all-in-one security platform used for managing building access control, video surveillance, and visitor management. A security flaw in version 3.0 allows unauthorized individuals to access sensitive files on the server by manipulating web addresses. This could lead to the theft of configuration data, source code, and other private information, potentially compromising the security of the entire facility management system.
Technical details
A directory traversal (file path manipulation) vulnerability exists in ZKTeco ZKBioSecurity 3.0, specifically within the 'xmlPath' parameter of the 'baseAction!getPageXML.action' component. By using traversal sequences (e.g., '../'), an unauthenticated remote attacker can bypass access controls to read sensitive files outside of the intended directory, such as 'WEB-INF/web.xml'. This can result in the disclosure of application configuration files, source code, and other protected resources. The vulnerability was tested on environments running Apache Tomcat 7.0.56 on Windows 7.
Affected products
- ZKTeco ZKBioSecurity 3.0.1.0_R_230 and earlier
Timeline
- 2016-07-18: disclosed: Initial discovery by Zero Science Lab
- 2016-08-31: other: Exploit published on Exploit-DB
- 2026-03-16: advisory: CVE assigned/published in NVD via VulnCheck
References
- https://cxsecurity.com/issue/WLB-2016090001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/116489
- https://packetstormsecurity.com/files/138570
- https://www.exploit-db.com/exploits/40326/
- https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-file-path-manipulation-vulnerability
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5365.php