Biometric Terminals Found to Have Vulnerabilities by Researchers

Published:

spot_img

Widespread Vulnerabilities in ZKTeco Biometric Terminals Discovered by Kaspersky Researchers

Kaspersky researchers have uncovered a series of critical vulnerabilities in biometric terminals developed by ZKTeco, raising concerns about potential security breaches in high-security environments. These flaws could allow threat actors to bypass authentication, steal sensitive data, and even take full control of the affected terminals.

The biometric terminals, which are widely used and distributed under various brand names, are commonly found in sensitive locations such as nuclear power plants, chemical plants, and hospitals. With the ability to store thousands of facial templates, these devices play a crucial role in ensuring security and access control.

Researchers identified 24 different vulnerabilities in ZKTeco biometric terminals, including SQL injection, buffer stack overflow, command injection, and arbitrary file write and read vulnerabilities. These flaws could be exploited by cybercriminals to gain unauthorized access, steal biometric data, and deploy backdoors for future attacks.

Georgy Kiguradze, Senior Application Security Specialist at Kaspersky, emphasized the diverse impact of these vulnerabilities, highlighting the risks of deepfake attacks and social engineering tactics. He urged immediate patching of these vulnerabilities to prevent potential data breaches and unauthorized access to restricted areas.

While the researchers have shared their findings with ZKTeco, it is unclear whether the vulnerabilities have been addressed. In the meantime, they recommend isolating biometric reader usage, strengthening administrator passwords, auditing security settings, minimizing QR code functionality, and regularly updating firmware to mitigate risks.

As organizations rely on biometric terminals for access control and security, it is crucial to address these vulnerabilities promptly to safeguard sensitive data and prevent potential security breaches. The urgency of patching these flaws underscores the importance of proactive security measures in high-risk environments.

spot_img

Related articles

Recent articles

Experts Warn: A Major Cybersecurity Breach in Healthcare is Inevitable

Rising Cybersecurity Threats in Healthcare: A Looming Crisis The Stark Reality of Cyber Incidents Experts in the healthcare field are sounding the alarm on cybersecurity threats,...

Iranian and Egyptian Foreign Ministers Discuss Key Issues in Phone Call

Iran and Egypt Celebrate Eid al-Adha with Diplomatic Dialogue A Warm Exchange of Greetings In a significant diplomatic interaction, Iranian Foreign Minister Seyed Abbas Araghchi and...

Malicious Browser Extensions Infect 722 Users in Latin America Since Early 2025

Emerging Cyber Threat: Malicious Extension Targets Brazilian Users Cybersecurity experts have recently uncovered a concerning campaign aimed at users in Brazil, which has been ongoing...

Searchlight Cyber Aids U.S. Government in Dismantling BidenCash Dark Web Marketplace

U.S. Law Enforcement Takes Down BidenCash Dark Web Marketplace Overview of the Operation In a significant law enforcement effort announced by the U.S. Department of Justice,...