Multiple vulnerabilities have been reported in ZKTeco WL20, which could allow an attacker to gain unauthorized access to sensitive information and Message Queuing Telemetry Transport (MQTT) broker associated with the targeted device.
Target Audience:
End-users/ Administrators of ZKTeco WL20 Biometric Attendance System
Risk Assessment:
Risk of exposure of credentials, private keys, configuration data, system data and MQTT endpoints.
Impact Assessment:
Impact on confidentiality and integrity of the vulnerable device.
CVE-2025-55279 and CVE-2025-55280:
- Apply mitigations as per vendor instructions (whenever available) or discontinue the use of the product if mitigations are unavailable.
- Perform risk assessment and implement physical security controls to prevent unauthorized access to the device.
The information provided herein is on "as is" basis, without warranty of any kind.