Notice Regarding Security Vulnerability in ZKBio CVSecurity 

2026-07-27

Dear Valued Customers,

 

This notice is to inform you of a security vulnerability identified in ZKBio CVSecurity V6.7.2 or earlier versions. It is essential to take the necessary actions to protect your systems for your attention to this matter.

 

1. Vulnerability Details

 

Scope of Impact: ZKBio CVSecurity V6.7.2 and earlier versions

Vulnerability Overview: A vulnerability that allows arbitrary file download has been identified. Successful exploitation of this vulnerability may result in information leakage.

 

2. Vulnerability Solution

 

A. Software upgrade: Upgrade to ZKBio CVSecurity V6.8.0 version or later, which includes the official fix.

B. Strengthening protections: If an immediate upgrade is not feasible, ensure that necessary mitigations are in place, such as closing external network ports for zkfinger-served and restricting access permissions to minimize exposure.

C. Data archive: Before performing any upgrade operations, please archive all relevant data to prevent potential data loss.

 

3. Contact Information

 

A. Please contact service-af-xm@zkteco.com to obtain the patch package for the fixed version.

B. You may call the ZKTeco customer service hotline at 400-6900-999 to request the patch package for the repaired version.

C. You may also contact the ZKTeco branch in your region to obtain the patch package for the repaired version.


ZKBio Partner

Digital Marketing & Service Platform

for ZKTeco Partners

Scan and download the app

This website uses cookies to store information on your device, cookies can enhance your user experience and help our website work normally.
For more information, please read our Cookie Policy and Privacy Policy.

Accept