Latest
Subscribe
Advertisement

Incident

ZKTeco camera config export exposes credentials without authentication

Company
ZKTeco
CVE ID
CVE-2026-8598
Severity
High
Source URL
www.cisa.gov
Vendor notified at
2026-05-19 00:00:00

CISA warned that an undocumented configuration-export port on ZKTeco CCTV cameras requires no authentication and exposes device account credentials — a network foothold risk for sites pairing ZKTeco video with access control.

Source: www.cisa.gov

The vendor was notified before publication and offered a response under our right-of-reply policy; none was given. Policy