Notice Regarding Security Vulnerability in ZKBio CVSecurity 6.5.0_R

2025-06-20

Dear Valued Customers,

 

This notice is to inform you of a security vulnerability identified in ZKBio CVSecurity Version 6.5.1_R or below. It is essential to take the necessary actions to protect your systems for your attention to this matter.

 

1. Vulnerability Details

 

Vulnerability Number: CNVD-C-2025-309064

Scope of Impact: ZKBio CVSecurity 6.5.1_R or below

Vulnerability Overview: A remote command injection vulnerability exists, successful exploitation of the vulnerability may lead to script injection.

 

2. Vulnerability Solution

 

This vulnerability has been addressed in ZKBio CVSecurity 6.5.2_R and above version. It is strongly recommended to update to the latest version.

 

A. Enhance protection: Before upgrading, ensure that the system has taken the necessary protective measures, such as closing the zkfinger-served extranet ports, restricting access privileges, etc.

 

B. Data backup: Before performing an upgrade, it is essential to back up relevant data to prevent data loss.

 

3. Contact Information

 

A. Please email service-af-xm@zkteco.com to obtain the patch package for the fixed version.

B. You may call the ZKTeco customer service hotline at 400-6900-999 to request the patch package for the repaired version.

C. You may also contact the ZKTeco branch in your region to obtain the patch package for the repaired version.


This website uses cookies to store information on your device, cookies can enhance your user experience and help our website work normally.
For more information, please read our Cookie Policy and Privacy Policy.

Accept