This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Aug 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the unencrypted credentials stored in the firmware of targeted device. | |
Title | Cleartext Storage Vulnerability in ZKTeco WL20 | |
Weaknesses | CWE-312 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-In
Published: 2025-08-13T11:12:16.853Z
Updated: 2025-08-13T13:10:37.654Z
Reserved: 2025-07-22T08:56:34.298Z
Link: CVE-2025-54464

Updated: 2025-08-13T13:10:34.565Z

Status : Awaiting Analysis
Published: 2025-08-13T12:15:25.927
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-54464

No data.