City
Epaper

24 bugs in Chinese biometric device can compromise data

By IANS | Updated: June 11, 2024 16:30 IST

New Delhi, June 11 Researchers have identified 24 vulnerabilities in the hybrid biometric terminal produced by Chinese manufacturer ...

Open in App

New Delhi, June 11 Researchers have identified 24 vulnerabilities in the hybrid biometric terminal produced by Chinese manufacturer ZKTeco.

According to the cybersecurity company Kaspersky, by adding random user data to the database or using a fake QR code, a threat actor can easily bypass the verification process and gain unauthorised access. Attackers can also steal and leak biometric data, remotely manipulate devices, and deploy backdoors.

High-security facilities worldwide are at risk if they use this vulnerable device, researchers warned. "In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device’s database, they can exploit other vulnerabilities to download a legitimate user’s photo, print it, and use it to deceive the device’s camera to gain access to a secured area," said Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

As per the researchers, the biometric readers in question are widely used in areas across diverse sectors such as nuclear or chemical plants to offices and hospitals. These devices support face recognition and QR-code authentication, along with the capacity to store thousands of facial templates.

All findings were proactively shared with the manufacturer before public disclosure, the researchers mentioned. "All the factors underscore the urgency of patching these vulnerabilities and thoroughly auditing the device's security settings for those using the devices in corporate areas,” said Kiguradze.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

MumbaiCharkop Firing CCTV Video: Horrific Shooting of Real Estate Agent Freddy D'Lima Caught on Camera

NationalCoal smuggling case: Cash, gold seized by ED during raids in Bengal, Jharkhand

NationalTremors felt in NE states, no damage reported

BusinessSEBI not considering any new digital gold framework: Tuhin Kanta Pandey

EntertainmentArjun Rampal Thanks Director Aditya Dhar for Transforming Dhurandhar’s Cast into Unrecognizable Forces On-Screen

Technology Realted Stories

TechnologyOperating profits of OMCs to surge 50 pc due to stronger marketing margins

TechnologyNobel laureate C V Raman a true legend who illuminated world of science-tech: Minister

TechnologyIndiGo board approves Rs 7,294 crore towards purchase of aviation assets

TechnologyIndia leads real estate investment momentum in Asia-Pacific: Report

TechnologyCDSCO labs flag 211 drug samples as ‘not of standard quality’ in October