LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2016-20024

CVE-2016-20024 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 16, 2026

ZKTeco ZKTime.Net - Privilege Escalation

Published: March 16, 2026Updated: March 16, 2026Remote Exploitable

Overview

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability caused by world-writable permissions on the ZKTimeNet3.0 directory and its contents, letting unprivileged users escalate privileges by modifying executable files, exploit requires unprivileged user access.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unprivileged users can escalate privileges by replacing executables with malicious binaries, potentially gaining full system control.

Mitigation

Update to the latest version with corrected file permissions.

Details

CVE ID
CVE-2016-20024
Severity
Critical
CVSS Score
9.8
Type
broken_access_control
Status
unconfirmed

CWE

  • CWE-538

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H