CVE-2022-42953
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Published:Dec 25, 2022
Last Modified:Apr 15, 2025
EPS:Dec 25, 2022
EPSS Score:0.08716
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Zkteco
Product
Zem500
Zkteco
Zem500
Vendor
Zkteco
Product
Zem500 Firmware
Zkteco
Zem500 Firmware
Vendor
Zkteco
Product
Zem510
Zkteco
Zem510
Vendor
Zkteco
Product
Zem510 Firmware
Zkteco
Zem510 Firmware
Vendor
Zkteco
Product
Zem560
Zkteco
Zem560
Vendor
Zkteco
Product
Zem560 Firmware
Zkteco
Zem560 Firmware
Vendor
Zkteco
Product
Zem600
Zkteco
Zem600
Vendor
Zkteco
Product
Zem600 Firmware
Zkteco
Zem600 Firmware
Vendor
Zkteco
Product
Zem720
Zkteco
Zem720
Vendor
Zkteco
Product
Zem720 Firmware
Zkteco
Zem720 Firmware
Vendor
Zkteco
Product
Zem760
Zkteco
Zem760
Vendor
Zkteco
Product
Zem760 Firmware
Zkteco
Zem760 Firmware
Vendor
Zkteco
Product
Zem800
Zkteco
Zem800
Vendor
Zkteco
Product
Zem800 Firmware
Zkteco
Zem800 Firmware
Vendor
Zkteco
Product
Zmm200
Zkteco
Zmm200
Vendor
Zkteco
Product
Zmm200 Firmware
Zkteco
Zmm200 Firmware
Vendor
Zkteco
Product
Zmm210
Zkteco
Zmm210
Vendor
Zkteco
Product
Zmm210 Firmware
Zkteco
Zmm210 Firmware
Vendor
Zkteco
Product
Zmm220
Zkteco
Zmm220
Vendor
Zkteco
Product
Zmm220 Firmware
Zkteco
Zmm220 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
