CVE-2022-42953 - CVE House
Back to Database
Status published Unknown CVE-2022-42953

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to...

Vulnerability Description

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-42953

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zmm200 firmware, zmm210 firmware, zmm220 firmware, zem720 firmware, zem600 firmware, zem800 firmware, zem510 firmware, zem560 firmware, zem760 firmware, zem500 firmware
Vulnerable Versions:
0

Timeline

Official Publish: December 25th, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.