ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.
References
Configurations
No configuration.
History
16 Mar 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:17
Updated : 2026-03-16 14:53
NVD link : CVE-2016-20030
Mitre link : CVE-2016-20030
CVE.ORG link : CVE-2016-20030
JSON object : View
Products Affected
No product.
CWE
CWE-551
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
