Description
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
Problem types
Product status
Any version before V5.0.1.2.20260421
V5.0.1.2.20260421
Credits
Souvik Kandar reported this vulnerability to CISA.
References
www.zkteco.com/en/announcement/23
www.cisa.gov/news-events/ics-advisories/icsa-26-139-04
github.com/...p/csaf_files/OT/white/2026/icsa-26-139-04.json