Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-20513 | ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 07 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zkteco zkbio WDMS v.8.0.5 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp. | ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp. |
| References |
|
Fri, 06 Jun 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in zkteco zkbio WDMS v.8.0.5 allows an attacker to execute arbitrary code via the /files/backup/ component. | zkteco zkbio WDMS v.8.0.5 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp. |
Fri, 25 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zkteco:zkbio_wdms:8.0.5:*:*:*:*:*:*:* |
Tue, 22 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zkteco
Zkteco zkbio Wdms |
|
| CPEs | cpe:2.3:a:zkteco:zkbio_wdms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zkteco
Zkteco zkbio Wdms |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-10T13:26:43.543Z
Reserved: 2024-01-11T00:00:00.000Z
Link: CVE-2024-22988
Updated: 2024-08-19T07:48:06.038Z
Status : Modified
Published: 2024-02-23T23:15:09.623
Modified: 2025-06-07T21:15:21.620
Link: CVE-2024-22988
No data.
OpenCVE Enrichment
No data.
EUVD