Junglewise Threat Intelligence

CVE-2025-7636: Ergosis ZEUS PDKS SQL injection

CVE-2025-7636 · Severity: high · CVSS 8.8 · Published 2026-02-10

Executive brief

Ergosis ZEUS PDKS, a personnel attendance control system used for tracking employee hours and access, contains a security vulnerability that could allow an attacker to interfere with its database. By exploiting this flaw, an authorized user could potentially view sensitive employee records, modify attendance data, or disrupt the system's operations. This could lead to payroll inaccuracies, unauthorized access to facilities, or the theft of personal information.

Technical details

A SQL injection vulnerability (CWE-89) exists in Ergosis ZEUS PDKS versions prior to 1.0.5.10 and up to 10022026. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an attacker with low-level authenticated access to inject malicious queries. This can be exploited over the network without user interaction to achieve full unauthorized access to the underlying database, including the ability to read, modify, or delete sensitive data. As of the disclosure date, the vendor has not responded to reports or provided a patch.

Affected products

  • Ergosis Security Systems Computer Industry and Trade Inc. ZEUS PDKS <1.0.5.10 through 10022026

Timeline

  • 2026-02-10: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-02-10: advisory: CVE-2025-7636 published

References