peter bassill · operator
$ cve CVE-2022-42953 JSON

CVE-2022-42953 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 5% (pctl 92)

Patch early

A public exploit exists.

Description

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS4.97% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-425
On CISA KEVno
Public exploityes
Published2022-12-25
Last modified2026-06-17

Affected (20)

VendorProduct
zktecozem500
zktecozem500 firmware
zktecozem510
zktecozem510 firmware
zktecozem560
zktecozem560 firmware
zktecozem600
zktecozem600 firmware
zktecozem720
zktecozem720 firmware
zktecozem760
zktecozem760 firmware
zktecozem800
zktecozem800 firmware
zktecozmm200
zktecozmm200 firmware
zktecozmm210
zktecozmm210 firmware
zktecozmm220
zktecozmm220 firmware

Public exploits

SourceTitleDate
exploit-dbZKTeco ZEM/ZMM 8.88 - Missing Authentication2023-03-28

References

→ the Explorer  ·  watch your stack  ·  NVD