ZKBio Time Vulnerability: Remote Photo Manipulation Exploit Disclosed
CVE-2024-11049
Key Information:
- Vendor
Zkteco
- Status
- Vendor
- CVE Published:
- 10 November 2024
Badges
What is CVE-2024-11049?
A vulnerability has been identified in the ZKTeco ZKBio Time 9.0.1, specifically within the unknown function of the Image File Handler located at /auth_files/photo/. This flaw allows for direct requests, which could enable a remote attacker to exploit the system. The complexity associated with launching an attack is regarded as relatively high, and public disclosures of the exploit suggest it may be viable. Although the vendor was informed prior to the disclosure, there has been no acknowledgment or response regarding the issue.
Affected Version(s)
ZKBio Time 9.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved