LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2016-20030

CVE-2016-20030 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 16, 2026

Published: March 16, 2026Updated: March 16, 2026Remote Exploitable

Overview

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Details

CVE ID
CVE-2016-20030
Severity
Critical
CVSS Score
9.8
Status
unconfirmed

CWE

  • CWE-551

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H