CVE-2026-8598Patch

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-20)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 2Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 205-1905-20
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-191
Patch1
2026-05-202
Disclosure1Patch1
Full discourse3 posts
  • yousukezan@yousukezan
    Disclosure

    ZKTeco製監視カメラで、認証不要で管理者認証情報を窃取できる重大脆弱性CVE-2026-8598が見つかった。攻撃者はネットワーク経由でカメラを完全乗っ取りし、監視映像閲覧や企業内部への侵入拠点化が可能になる。 問題はZKTeco製CCTV「SSC335-GC2063-Face-0b77」系に存在する未公開の設定エクスポート用ポートだ。このポートには認証機構がなく、ネットワーク到達可能な攻撃者なら誰でも接続できる。問い合わせを行うだけで、稼働サービス一覧や管理者アカウント認証情報など機密データがそのまま返される。 攻撃者は単一リクエストで認証情報を取得し、ライブ映像閲覧、設定改変、デバイス悪用を実行できる。CVSSは9.1で、ユーザー操作不要なため自動スキャンによる大規模侵害も容易とされる。 特に危険なのは、CCTVが社内ネットワークと同一セグメントに接続されている環境だ。侵害されたカメラは持続的バックドアとなり、内部サーバーへの横展開にも利用される可能性がある。 ZKTecoは既に修正版「V5.0.1.2.20260421」を公開しており、未公開ポートを閉鎖した。利用組織には即時ファーム更新に加え、IoT・監視機器を本番ネットワークから分離し、インターネットへ直接公開しない構成が推奨されている。 https://securityonline.info/zkteco-cctv-camera-vulnerability-cve-2026-8598-admin-credentials-leak/

    Post summary

    The post announces the discovery of CVE‑2026‑8598 in ZKTeco CCTV cameras, detailing an unauthenticated port that leaks admin credentials and outlines a patch release and mitigation steps.

    010501.2K
    14.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    ZKTeco patches a critical 9.1 CVSS flaw (CVE-2026-8598) in CCTV cameras leaking admin credentials without authentication. Upgrade your firmware now! #ZKTeco #IoTSecurity #PhysicalSecurity #CyberSecurity #InfoSec #VulnerabilityAlert #CVE20268598 #CCTV https://securityonline.info/zkteco-cctv-camera-vulnerability-cve-2026-8598-admin-credentials-leak/ https://t.co/a0B49F1Pxh

    Post summary

    The tweet alerts to a critical CVE‑2026‑8598 in ZKTeco CCTV cameras that leaks admin credentials, and urges users to apply the vendor’s firmware patch.

    00000271
    12.2K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-8598 is the gift that keeps on giving: unauthenticated config export dumping camera credentials. In ICS land, that’s basically “buy access with the box.” Patch yesterday. #Windows #Security https://windowsforum.com/threads/cisa-warns-zkteco-cctv-cve-2026-8598-unauthenticated-config-export-exposes-credentials.418960/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CredentialExposure #CisaAdvisory #FirmwareUpdates https://t.co/hOweDDWR4w

    Post summary

    The tweet reports CVE-2026-8598, details an unauthenticated credential‑dumping flaw via config export, and notes that a patch was released yesterday.

    0000072
    1.1K followersView on X

Explore more