CRITICAL🇵🇱 Wersja polska

CVE-2016-20030

CVSS 9.3v4.0pub. 2026-03-16upd. 2026-06-08

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.

🤖 AI Analysis
How it works

An attacker sends HTTP requests to the authLoginAction!login.do script, providing various partial character strings in the username parameter. The application returns different responses depending on whether the provided fragment corresponds to an existing user account. Based on analysis of these response differences, it is possible to systematically discover and confirm valid account names without requiring any authentication.

Impact

An attacker is able to identify a list of valid usernames in the ZKBioSecurity system, which can be leveraged as a starting point for further attacks, such as dictionary attacks or brute-force password attacks on these accounts.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the application's web interface only to trusted networks and implement monitoring and blocking mechanisms for suspicious numbers of requests to the authLoginAction!login.do endpoint.

Who is affected

ZKTeco ZKBioSecurity version 3.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References