Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27273 | A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input ../../../../zkbio_media.sql leads to path traversal: '../filedir'. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.3 Build 2025-05-26-1605 is able to address this issue. It is recommended to upgrade the affected component. |
Tue, 10 Jun 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zkteco:zkbio_media:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Tue, 10 Jun 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input ../../../../zkbio_media.sql leads to path traversal: '../filedir'. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256272. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input ../../../../zkbio_media.sql leads to path traversal: '../filedir'. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.3 Build 2025-05-26-1605 is able to address this issue. It is recommended to upgrade the affected component. |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV4_0
|
Thu, 13 Mar 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zkteco
Zkteco zkbio Media |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:zkteco:zkbio_media:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zkteco
Zkteco zkbio Media |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-10T07:28:04.921Z
Reserved: 2024-03-08T06:48:01.928Z
Link: CVE-2024-2318
Updated: 2024-08-01T19:11:53.421Z
Status : Modified
Published: 2024-03-08T13:15:07.950
Modified: 2026-04-29T01:00:01.613
Link: CVE-2024-2318
No data.
OpenCVE Enrichment
No data.
EUVD