CVE-2024-35428: ZKTeco Zkbio Cvsecurity

High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.

Affected products

  • ZKTeco Zkbio Cvsecurity: version 6.1.1 only

Published 2024-05-30. Last modified 2026-06-17.