Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35334 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:* |
Thu, 15 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1. |
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zkteco
Zkteco zkbio Cvsecurity |
|
| CPEs | cpe:2.3:a:zkteco:zkbio_cvsecurity:6.11:*:*:*:*:*:*:* | |
| Vendors & Products |
Zkteco
Zkteco zkbio Cvsecurity |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-15T21:17:59.787Z
Reserved: 2024-05-17T00:00:00.000Z
Link: CVE-2024-35431
Updated: 2024-08-02T03:14:53.145Z
Status : Analyzed
Published: 2024-05-30T17:15:34.277
Modified: 2025-06-17T19:17:36.790
Link: CVE-2024-35431
No data.
OpenCVE Enrichment
No data.
EUVD