CVE-2024-35431

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*

History

17 Jun 2025, 19:17

Type Values Removed Values Added
References () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md - () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md - Exploit
First Time Zkteco
Zkteco zkbio Cvsecurity
CPE cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*

15 May 2025, 22:15

Type Values Removed Values Added
Summary ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.

30 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 17:15

Updated : 2025-06-17 19:17


NVD link : CVE-2024-35431

Mitre link : CVE-2024-35431


JSON object : View

Products Affected

zkteco

  • zkbio_cvsecurity
CWE

No CWE.