HarborGuard / CVE
Back to search
CRITICALCVE-2026-8598Published Modified CNA icscert

CVE-2026-8598: Unauthenticated Export Service in ZKTeco CCTV Cameras

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

Metrics

CVSS v4.0
9.1
Severity
CRITICAL
Fixed in
V5.0.1.2.20260421
Affected Products
1

Fix available

V5.0.1.2.20260421
Affected packages
  • ZKTeco / SSC335-GC2063-Face-0b77 Solution Camera
    < V5.0.1.2.20260421 (from 0)
    Fixed in V5.0.1.2.20260421
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N