PT-2025-21029 · Zkt · Zkbio Cvsecurity
Published
2025-05-13
·
Updated
2025-05-13
·
CVE-2025-45746
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ZKT ZKBio CVSecurity version 6.4.1 R
Description:
An unauthenticated attacker can craft a JWT token using a hardcoded secret to authenticate to the service console.
Recommendations:
For ZKT ZKBio CVSecurity version 6.4.1 R, update the software to remove the hardcoded secret and utilize a secure method for token authentication. As a temporary workaround, consider restricting access to the service console to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zkbio Cvsecurity