PT-2025-32981 · Zkteco · Zkteco Wl20

CVE-2025-55279

·

Published

2025-08-13

·

Updated

2025-08-13

CVSS v4.0

6.9

Medium

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ZKTeco WL20 (affected versions not specified)
Description: The device stores a private key in plaintext within its firmware. An attacker with physical access can extract the firmware, analyze the binary data, and retrieve the private key. Successful exploitation could allow an attacker to perform unauthorized decryption of sensitive data and Man-in-the-Middle (MitM) attacks on the targeted device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55279

Affected Products

Zkteco Wl20