Unencrypted Credential Storage in ZKTeco WL20 Vulnerability
CVE-2025-54464

7HIGH

Key Information:

Vendor

Zkteco Co

Vendor
CVE Published:
13 August 2025

What is CVE-2025-54464?

The vulnerability in ZKTeco WL20 exposes admin and user credentials stored in the device firmware due to inadequate encryption measures. Attackers with physical access can exploit this weakness by extracting the firmware and reverse engineering the binary data, allowing them to obtain unencrypted credentials. This creates a significant security risk as unauthorized users could gain access to sensitive information and functionality associated with the device. It is crucial for users of the ZKTeco WL20 to be aware of this vulnerability and take necessary actions to mitigate potential risks.

Affected Version(s)

WL20 Biometric Attendance System <=ZLM31-FXO1-3.1.8

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Shravan Singh from Kavach IoT Security.
.