news.mlab.sh
Back to the feed
vulnerability

ZKTeco CCTV Cameras

Medium
Summary

A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. This flaw stems from an undocumented export port that doesn't require authentication, posing a risk to organizations deploying these cameras worldwide. ZKTeco has released a patch, but proactive mitigation measures are recommended to minimize potential exploitation.

The vulnerability centers around an unsecured export port present in certain ZKTeco CCTV camera models. This port, lacking authentication, exposes sensitive details including open services and camera account credentials. This represents a significant security risk, particularly for organizations utilizing these cameras within critical infrastructure sectors like commercial facilities. The widespread deployment of these cameras globally, coupled with the ease of exploitation, amplifies the potential impact of a successful attack.

Read the full article at CISA Advisories