Critical severity9.8NVD Advisory· Published Feb 23, 2024· Updated Jun 17, 2026
CVE-2024-22988
CVE-2024-22988
Description
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zkteco:zkbio_wdms:8.0.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:zkteco:zkbio_wdms:8.0.5:*:*:*:*:*:*:*
- (no CPE)range: <9.0.2 Build 20250526
- ZKteco/ZKBio WDMSdescription
Patches
Vulnerability mechanics
References
4- gist.github.com/whiteman007/b50a9b64007a5d7bcb7a8bee61d2cb47nvdThird Party Advisory
- www.vicarius.io/vsociety/posts/revealing-cve-2024-22988-a-unique-dive-into-exploiting-access-control-gaps-in-zkbio-wdms-uncover-the-untold-crafted-for-beginners-with-a-rare-glimpse-into-pentesting-strategiesnvdThird Party Advisory
- zkteco.comnvdProduct
- www.zkteco.com/en/Security_Bulletinsibs/12nvd
News mentions
0No linked articles in our index yet.