ZKTeco CCTV cameras contain an unauthenticated configuration export port exposing camera…
ZKTeco CCTV cameras contain an unauthenticated configuration export port exposing camera credentials and service information; patch available.
CISA has disclosed CVE-2026-8598, an authentication bypass vulnerability affecting ZKTeco CCTV cameras model SSC335-GC2063-Face-0b77 running firmware versions prior to V5.0.1.2.20260421. The vulnerability stems from an undocumented configuration export port that requires no authentication, allowing remote attackers to access critical camera information including account credentials and details about open services. This represents a significant security risk for organizations deploying these cameras in commercial facilities.
ZKTeco has released firmware version V5.0.1.2.20260421 to address this vulnerability and recommends immediate deployment. The vendor has published a security advisory with additional remediation guidance. While no active exploitation has been reported to CISA at the time of this advisory, the ease of exploitation and sensitive nature of exposed credentials warrant urgent patching. Organizations should prioritize upgrading affected devices and implementing network segmentation to limit exposure of ICS/IoT devices to untrusted networks.
The vulnerability was responsibly disclosed by security researcher Souvik Kandar. CISA emphasizes standard ICS security best practices including network isolation, firewall deployment, and use of VPNs for remote access as complementary defensive measures beyond patching.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free