CVE-2016-20030

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.
Configurations

No configuration.

History

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-03-16 14:53


NVD link : CVE-2016-20030

Mitre link : CVE-2016-20030

CVE.ORG link : CVE-2016-20030


JSON object : View

Products Affected

No product.

CWE
CWE-551

Incorrect Behavior Order: Authorization Before Parsing and Canonicalization