ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation
Summary
| CVE | CVE-2016-20024 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-16 14:17:48 UTC |
| Updated | 2026-06-08 16:16:31 UTC |
| Description | ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation. |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-538 | CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ZKTeco Inc. | ZKTeco ZKTime.Net | affected 3.0.1.6 | Not specified |
| CNA | ZKTeco Inc. | ZKTeco ZKTime.Net | affected 3.0.1.5 (160622) | Not specified |
| CNA | ZKTeco Inc. | ZKTeco ZKTime.Net | affected 3.0.1.1 (160216) | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| exchange.xforce.ibmcloud.com/vulnerabilities/116487 | [email protected] | exchange.xforce.ibmcloud.com | |
| packetstormsecurity.com/files/138565 | [email protected] | packetstormsecurity.com | |
| cxsecurity.com/issue/WLB-2016080264 | [email protected] | cxsecurity.com | |
| www.exploit-db.com/exploits/40322 | [email protected] | www.exploit-db.com | |
| www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5360.php | [email protected] | www.zeroscience.mk | |
| www.vulncheck.com/advisories/zkteco-zktime-net-insecure-file-permissions-privil... | [email protected] | www.vulncheck.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: LiquidWorm as Gjoko Krstic of Zero Science Lab (en)
Additional Advisory Data
Solutions
CNA: The affected software ZKTime.Net has been officially discontinued. It is recommended that all users switch to using ZKBio Time.Net software. ZKBio Time.Net has fixed this vulnerability. It is recommended that users use the latest version of ZKBio Time.Net to eliminate the risk.