Security Advisory

CVE-2016-20031

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-15 13:35:35
Last updated 2026-03-16 14:20:19
Assigner VulnCheck
State PUBLISHED

Description

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and authenticates using the IP as username with hardcoded password 123456 to access sensitive information and perform unauthorized actions.