CVE-2016-20029

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-16 14:17

Updated : 2026-03-16 14:53


NVD link : CVE-2016-20029

Mitre link : CVE-2016-20029

CVE.ORG link : CVE-2016-20029


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions