Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5w3w-4xg4-wwhf

Опубликовано: 16 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.

EPSS

Процентиль: 8%
0.00028
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-538

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.

EPSS

Процентиль: 8%
0.00028
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-538