Medium severity5.5NVD Advisory· Published Mar 16, 2026· Updated Jun 8, 2026
CVE-2016-20031
CVE-2016-20031
Description
ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and authenticates using the IP as username with hardcoded password 123456 to access sensitive information and perform unauthorized actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 3.0
Patches
Vulnerability mechanics
References
6- cxsecurity.com/issue/WLB-2016090003nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/116488nvd
- packetstormsecurity.com/files/138571nvd
- www.exploit-db.com/exploits/40327/nvd
- www.vulncheck.com/advisories/zkteco-zkbiosecurity-local-authorization-bypass-via-vislogin-jspnvd
- www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5367.phpnvd
News mentions
0No linked articles in our index yet.