CVE-2016-20031 identifies a local authorization bypass vulnerability within ZKTeco ZKBioSecurity 3.0's visLogin.jsp component. This flaw allows a local attacker to authenticate without valid credentials by spoofing localhost requests, specifically by exploiting how the system treats the IPv6 loopback address as 127.0.0.1 and authenticates with a hardcoded password. Rated with a CVSS score of 5.5 (Medium), successful exploitation grants high confidentiality impact, enabling access to sensitive information and unauthorized actions. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ZKTeco Inc. | ZKTeco ZKBioSecurity | 3.0.1.0_R_230CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.