CVE-2024-35431

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*

History

17 Jun 2025, 19:17

Type Values Removed Values Added
CPE cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*
First Time Zkteco zkbio Cvsecurity
Zkteco
References () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md - () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md - Exploit
Summary (en) ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. (en) ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.

Information

Published : 2024-05-30 17:15

Updated : 2025-06-17 19:17


NVD link : CVE-2024-35431

Mitre link : CVE-2024-35431

CVE.ORG link : CVE-2024-35431


JSON object : View

Products Affected

zkteco

  • zkbio_cvsecurity
CWE
CWE-31

Path Traversal: 'dir\..\..\filename'