CVE-2016-20025
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/03/2026
Last modified:
15/04/2026
Description
ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for privilege escalation.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2016080265
- https://exchange.xforce.ibmcloud.com/vulnerabilities/116486
- https://packetstormsecurity.com/files/138566
- https://www.exploit-db.com/exploits/40323/
- https://www.vulncheck.com/advisories/zkteco-zkaccess-professional-privilege-escalation-via-insecure-permissions
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5361.php



