CVE-2016-20026 describes a critical vulnerability in ZKTeco ZKBioSecurity 3.0, where hardcoded credentials in its bundled Apache Tomcat server allow unauthenticated access to the manager application. Rated 9.8 Critical, this flaw enables attackers to use these credentials to upload malicious WAR archives and achieve arbitrary code execution with SYSTEM privileges over the network with low complexity and no user interaction. Despite its severe impact, there is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB. Furthermore, community discussion and media coverage regarding this CVE are absent, suggesting a lack of widespread attention or observed exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ZKTeco Inc. | ZKTeco ZKBioSecurity | 3.0.1.0_R_230CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.