PT-2025-32981 · Zkteco · Zkteco Wl20
Published
2025-08-13
·
Updated
2025-08-13
·
CVE-2025-55279
CVSS v4.0
6.9
Medium
| Vector | AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
ZKTeco WL20 (affected versions not specified)
Description:
The device stores a private key in plaintext within its firmware. An attacker with physical access can extract the firmware, analyze the binary data, and retrieve the private key. Successful exploitation could allow an attacker to perform unauthorized decryption of sensitive data and Man-in-the-Middle (MitM) attacks on the targeted device.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zkteco Wl20