CVE-2020-3934: Secom Dr.id Access Control

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.

Affected products

  • Secom Dr.id Access Control: before 3.3.2 (fixed in 3.3.2)
  • Secom Dr.id Attendance System: before 3.3.0.3_20160517 (fixed in 3.3.0.3_20160517)

Published 2020-02-11. Last modified 2026-06-17.