TL;DR:
- An analysis of ZKTeco’s biometric access system uncovered 24 critical security flaws.
- Attackers could bypass verification, steal biometric data, and deploy backdoors.
An analysis of a hybrid biometric access system from Chinese manufacturer ZKTeco has uncovered two dozen security flaws that could be used by attackers to defeat authentication, steal biometric data, and even deploy malicious backdoors. The vulnerabilities include six SQL injections, seven stack-based buffer overflows, five command injections, four arbitrary file writes, and two arbitrary file reads. These flaws could allow attackers to sell stolen biometric data, manipulate devices, and infiltrate critical networks for cyber espionage.
Kaspersky, the Russian cybersecurity firm that identified the flaws, recommends moving biometric reader usage into a separate network segment, using strong administrator passwords, improving device security settings, minimizing the use of QR codes, and keeping systems up-to-date to mitigate the risk of attacks. The message is clear – advanced technology like biometrics must be secured properly to prevent unauthorized access and data breaches.