Junglewise Threat Intelligence

CVE-2026-8598: ZKTeco CCTV Cameras auth bypass via undocumented port

CVE-2026-8598 · Severity: critical · CVSS 9.1 · Published 2026-05-20

Vendors: Zkteco.

Executive brief

ZKTeco CCTV cameras, used for video surveillance and security monitoring, contain a security flaw that allows unauthorized access to sensitive device information. An undocumented communication port is left open, which can be accessed over the network without a password. An attacker could use this to steal camera account credentials and view configuration details, potentially compromising the entire security camera system and its video feeds.

Technical details

An authentication bypass vulnerability (CWE-288) exists in certain ZKTeco CCTV camera models due to an undocumented configuration export port. This port is accessible over the network and does not require any authentication to provide a full export of the device configuration. A remote, unauthenticated attacker can exploit this to retrieve critical information, including camera account credentials and details about open services. The vulnerability is confirmed in the SSC335-GC2063-Face-0b77 solution. ZKTeco has released firmware version V5.0.1.2.20260421 to remediate this issue.

Affected products

  • ZKTeco CCTV Cameras SSC335-GC2063-Face-0b77 Solution < V5.0.1.2.20260421

Timeline

  • 2026-05-19: advisory: Initial ICS Advisory (ICSA-26-139-04) published by CISA
  • 2026-05-20: disclosed: CVE-2026-8598 published to the NVD
  • 2026-04-21: patched: Firmware version V5.0.1.2.20260421 released to address the vulnerability

References