CVE-2022-42953
Severity CVSS v4.0:
Pending analysis
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
25/12/2022
Last modified:
15/04/2025
Description
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zkteco:zmm200_firmware:*:*:*:*:*:*:*:* | 15.00 (excluding) | |
| cpe:2.3:h:zkteco:zmm200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zmm210_firmware:*:*:*:*:*:*:*:* | 15.00 (excluding) | |
| cpe:2.3:h:zkteco:zmm210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zmm220_firmware:*:*:*:*:*:*:*:* | 15.00 (excluding) | |
| cpe:2.3:h:zkteco:zmm220:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zem720_firmware:*:*:*:*:*:*:*:* | 8.88 (excluding) | |
| cpe:2.3:h:zkteco:zem720:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zem600_firmware:*:*:*:*:*:*:*:* | 8.88 (excluding) | |
| cpe:2.3:h:zkteco:zem600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zem800_firmware:*:*:*:*:*:*:*:* | 8.88 (excluding) | |
| cpe:2.3:h:zkteco:zem800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zem510_firmware:*:*:*:*:*:*:*:* | 8.88 (excluding) | |
| cpe:2.3:h:zkteco:zem510:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zkteco:zem560_firmware:*:*:*:*:*:*:*:* | 8.88 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



