CVE-2019-16398: Keeper k5 Firmware
Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
Affected products
- Keeper k5 Firmware: version 20.1.0.25 only; version 20.1.0.63 only
Published 2019-09-19. Last modified 2026-06-17.