PT-2026-25729 · Undefined · Undefined

Published

2026-03-15

·

Updated

2026-06-08

·

CVE-2016-20031

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZKTeco ZKBioSecurity version 3.0
Description The software contains a local authorization bypass in the visLogin.jsp component. This allows attackers to authenticate without valid credentials by spoofing localhost requests. The EnvironmentUtil.getClientIp() method incorrectly treats the IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1. Attackers can then authenticate using the IP address as the username with a hardcoded password of 123456, gaining access to sensitive information and performing unauthorized actions.
Recommendations Versions prior to 3.0 should be used.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20031

Affected Products

Undefined