ZKTeco camera config export exposes credentials without authentication
- Company
- ZKTeco
- CVE ID
- CVE-2026-8598
- Severity
- High
- Source URL
- www.cisa.gov
- Vendor notified at
- 2026-05-19 00:00:00
CISA warned that an undocumented configuration-export port on ZKTeco CCTV cameras requires no authentication and exposes device account credentials — a network foothold risk for sites pairing ZKTeco video with access control.
Source: www.cisa.gov