CVE-2026-8598CRITICAL 9.1EPSS p39.2%
CVE-2026-8598CVE-2026-8598
Description
An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.
Scoring
| CVSS 3.1 | 9.1 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.51% probability of exploitation · percentile 39.2% · 2026-06-18T12:00:27Z |
| Published | 2026-05-20 |
| Last modified | 2026-06-16 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass Using an Alternate Path or Channelcwe-288 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.