CVE-2020-3935: Secom Dr.id Access Control

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

Affected products

  • Secom Dr.id Access Control: version 3.3.2 only
  • Secom Dr.id Attendance System: before 3.3.0.3_20160517 (fixed in 3.3.0.3_20160517)

Published 2020-02-11. Last modified 2026-06-17.