CVE-2022-36634 – ZKSecurity BIO 3.0.5.0_R Privilege Escalation
https://notcve.org/view.php?id=CVE-2022-36634
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request. Un problema de control de acceso en ZKTeco ZKBioSecurity V5000 versión 3.0.5_r permite a atacantes crear arbitrariamente usuarios administradores por medio de una petición HTTP diseñada ZKSecurity BIO version 3.0.5.0_R suffers from a privilege escalation vulnerability. • http://zkbiosecurity.com http://zkteco.com https://seclists.org/fulldisclosure/2022/Sep/29 • CWE-863: Incorrect Authorization •
CVE-2022-36635 – ZKSecurity BIO 4.1.2 SQL Injection / Code Execution
https://notcve.org/view.php?id=CVE-2022-36635
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. Se ha detectado que ZKteco ZKBioSecurity V5000 versión 4.1.3, contiene una vulnerabilidad de inyección SQL por medio del componente /baseOpLog.do ZKSecurity BIO version 4.1.2 suffers from a remote SQL injection vulnerability that can allow for remote code execution. • http://zkbiosecurity.com http://zkteco.com https://medium.com/stolabs/cve-2022-36635-a-sql-injection-in-zksecuritybio-to-rce-c5bde2962d47 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •