Token-Reuse Vulnerability in ZKTeco FaceDepot 7B and ZKBiosecurity Server
CVE-2020-17474
9.8CRITICAL
What is CVE-2020-17474?
A token-reuse vulnerability in ZKTeco FaceDepot 7B version 1.0.213 and ZKBiosecurity Server version 1.0.0_20190723 enables attackers to exploit insufficient token validation. This security flaw allows malicious users to create arbitrary new accounts, consolidate existing users' privileges to administrative levels, remove users from the system, and extract facial data from the database, posing a significant risk to user privacy and application integrity.