Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bypassing ZkTeco-based OEM devices/ZKTeco biometric authentication system via SQLi in QR code
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM devices allows an attacker to authenticate under any user from the device database. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly others.
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
ZkTeco OEM SQL注入漏洞
Vulnerability Description
ZkTeco OEM是中国ZkTeco公司的一款智能系统。 ZkTeco OEM存在SQL注入漏洞,该漏洞源于SQL 命令中使用的特殊元素的不正确中和,允许攻击者在设备数据库中的任何用户下进行身份验证。以下产品及版本受到影响:ZkTeco ProFace X、Smartec ST-FR043、Smartec ST-FR041ME、ZAM170-NF-1.8.25-7354-Ver1.0.0版本。
CVSS Information
N/A
Vulnerability Type
N/A