PT-2025-32981 · Zkteco · Zkteco Wl20

Published

2025-08-13

·

Updated

2025-08-13

·

CVE-2025-55279

CVSS v4.0

6.9

Medium

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ZKTeco WL20 (affected versions not specified)
Description: The device stores a private key in plaintext within its firmware. An attacker with physical access can extract the firmware, analyze the binary data, and retrieve the private key. Successful exploitation could allow an attacker to perform unauthorized decryption of sensitive data and Man-in-the-Middle (MitM) attacks on the targeted device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-55279

Affected Products

Zkteco Wl20