ZKTeco Biometric System vulnerable to 24 critical security flaws discovered

June 14, 2024
1 min read




ZKTeco Biometric System Vulnerabilities

TL;DR:

  • An analysis of ZKTeco’s biometric access system uncovered 24 critical security flaws.
  • Attackers could bypass verification, steal biometric data, and deploy backdoors.

An analysis of a hybrid biometric access system from Chinese manufacturer ZKTeco has uncovered two dozen security flaws that could be used by attackers to defeat authentication, steal biometric data, and even deploy malicious backdoors. The vulnerabilities include six SQL injections, seven stack-based buffer overflows, five command injections, four arbitrary file writes, and two arbitrary file reads. These flaws could allow attackers to sell stolen biometric data, manipulate devices, and infiltrate critical networks for cyber espionage.

Kaspersky, the Russian cybersecurity firm that identified the flaws, recommends moving biometric reader usage into a separate network segment, using strong administrator passwords, improving device security settings, minimizing the use of QR codes, and keeping systems up-to-date to mitigate the risk of attacks. The message is clear – advanced technology like biometrics must be secured properly to prevent unauthorized access and data breaches.


Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives