of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.
Project Subscriptions
No data.
No advisories yet.
Solution
ZKTeco has patched this vulnerability in firmware version V5.0.1.2.20260421. ZKTeco recommends that users upgrade to firmware version V5.0.1.2.20260421 or later at their earliest opportunity.
Workaround
No workaround given by the vendor.
Wed, 20 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials. | |
| Title | Unauthenticated Export Service in ZKTeco CCTV Cameras | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-20T15:27:49.460Z
Reserved: 2026-05-14T14:10:56.160Z
Link: CVE-2026-8598
Updated: 2026-05-20T15:27:45.714Z
Status : Received
Published: 2026-05-20T16:16:27.707
Modified: 2026-05-20T16:16:27.707
Link: CVE-2026-8598
No data.
OpenCVE Enrichment
Updated: 2026-05-20T16:30:14Z