A popular hybrid biometric terminal manufactured by ZKTeco has been found to have several critical vulnerabilities, including a significant flaw that allows for SQL injection via QR codes.
This discovery raises serious concerns about the security of biometric access control systems, which are widely used in various high-security environments.
Biometric terminals are advanced devices used for personal identification and access control.
According to the SecureList report, they rely on unique human physical characteristics such as fingerprints, facial features, voice, or iris patterns to verify identity.
These terminals are often employed in sensitive areas like server rooms, executive offices, and hazardous facilities, including nuclear power plants and chemical plants. They record employees’ work hours, enhancing productivity and reducing fraud.
Analyze any MaliciousURL, Files & Emails & Configuration With ANY RUN : Start your Analysis
Biometric terminals offer several advantages:
However, they also have downsides:
The ZKTeco hybrid biometric terminal supports multiple authentication methods, including facial recognition, passwords, electronic passes, and QR codes.
The device has several physical interfaces, such as RJ45, RS232, and RS485, and can be connected to other scanners or authentication methods.
The security analysis revealed several vulnerabilities:
The vulnerabilities allow attackers to:
The discovery of these vulnerabilities in a widely used biometric terminal underscores the importance of rigorous security measures in designing and deploying biometric systems.
While biometric terminals offer significant benefits in terms of security and efficiency, they also introduce new risks that must be carefully managed.
Organizations using such devices should ensure they are correctly configured and regularly updated to mitigate potential security threats.
Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…