Authentication Bypass in ZKT ZKBio CVSecurity Software
CVE-2025-45746
9.8CRITICAL
What is CVE-2025-45746?
In ZKT ZKBio CVSecurity version 6.4.1_R, an unauthenticated attacker can exploit a flaw that allows them to craft JSON Web Tokens (JWTs) using a hardcoded secret. This vulnerability enables attackers to authenticate themselves to the service console without authorization, potentially leading to unauthorized access and control over the affected system.
Affected Version(s)
ZKBio CVSecurity 6.4.1_R < 6.6.0_R