CRITICALCVE-2026-8598Published Modified CNA icscert
CVE-2026-8598: Unauthenticated Export Service in ZKTeco CCTV Cameras
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
Metrics
- CVSS v4.0
- 9.1
- Severity
- CRITICAL
- Fixed in
- V5.0.1.2.20260421
- Affected Products
- 1
Fix available
V5.0.1.2.20260421
Affected packages
- ZKTeco / SSC335-GC2063-Face-0b77 Solution Camera< V5.0.1.2.20260421 (from 0)Fixed in V5.0.1.2.20260421
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NReferences