CVE-2016-20030
ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.56%
- CWE
- CWE-551
- Published
- 2026-03-15
- Last modified
- 2026-07-28
Affected products
- ZKTeco Inc. ZKTeco ZKBioSecurity
Weakness type
Related vulnerabilities
- CVE-2023-23924 — URI validation failure on SVG parsing in Dompdf
- CVE-2021-34429 — For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
- CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
- CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re
- CVE-2023-6394 — Quarkus: graphql operations over websockets bypass
- CVE-2021-31384 — Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
- CVE-2021-32779 — Incorrectly handling of URI '#fragment' element as part of the path element
- CVE-2021-32777 — Incorrect concatenation of multiple value request headers in ext-authz extension