Loading HuntDB...

GHSA-mvc4-fr9f-g4j8

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability in ZkTeco-based OEM devices allows OS
Command Injection.
Since all the found command implementations are executed from the
superuser, their impact is the maximum possible.
This issue affects
ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec
ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0
and possibly other.

Related CVEs

Key Information

GHSA ID
GHSA-mvc4-fr9f-g4j8
Published
May 21, 2024 12:30 PM
Last Modified
May 21, 2024 12:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.