ADVERTISEMENT
Monday, April 27, 2026
No Result
View All Result
The AZB More Than Just News
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION
No Result
View All Result
Daily The Azb
No Result
View All Result
Home PAKISTAN Islamabad

Chinese biometric access systems can be hacked, users data at risk: Kaspersky Kaspersky finds vulnerabilities in Chinese biometric access systems.

News Desk by News Desk
June 13, 2024
Chinese biometric access systems can be hacked, users data at risk: Kaspersky Kaspersky finds vulnerabilities in Chinese biometric access systems.
Share on FacebookShare on Twitter

High-security facilities worldwide using chinese biometric system are at risk: Kaspersky.

Islamabad: Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by International Chinese manufacturer ZKTeco. By adding random user data to the database or using a fake QR code, a nefarious actor can easily bypass the verification process and gain unauthorized access. Attackers can also steal and leak biometric data, remotely manipulate devices, and deploy back doors. High-security facilities worldwide are at risk if they use this vulnerable device.

Advertisements

The flaws were discovered in the course of Kaspersky Security Assessment experts’ research into the software and hardware of ZKTeco’s white-label devices. All findings were proactively shared with the manufacturer prior to public disclosure.

The biometric readers in question are widely used in areas across diverse sectors – from nuclear or chemical plants to offices and hospitals. These devices support face recognition and QR-code authentication, along with the capacity to store thousands of facial templates. However, the newly discovered vulnerabilities expose them to various attacks.

 Attackers can inject specific data into the QR code used for accessing restricted areas. Consequently, they can gain unauthorized access to the terminal and physically access the restricted areas. When the terminal processes a request containing this type of malicious QR code, the database mistakenly identifies it as originating from the most recently authorized legitimate user.

“In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device’s database, they can exploit other vulnerabilities to download a legitimate user’s photo, print it, and use it to deceive the device’s camera to gain access to a secured area. This method, of course, has certain limitations. It requires a printed photo, and warmth detection must be turned off. However, it still poses a significant potential threat,” says Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

Exploiting these vulnerabilities grants a potential attacker access to any file on the system and enables them to extract it. This includes sensitive biometric user data and password hashes to further compromise the corporate credentials. Threat actors can not only access and steal but also remotely alter the database of a biometric reader. “The impact of the discovered vulnerabilities is alarmingly diverse.Attackers can sell stolen biometric data on the dark web, subjecting affected individuals to increased risks of deepfake and sophisticated social engineering attacks. Furthermore, the ability to alter the database weaponizes the original purpose of the access control devices, potentially granting access to restricted areas for nefarious actors, Georgy Kiguradze further elaborated, .

To thwart related cyber attacks, Kaspersky advises Isolating biometric reader usage into a separate network segment and employ robust administrator passwords, changing default ones. Consider enabling or adding temperature detection to avoid authorization using a random photo and minimize the use of QR-code functionality, if feasible and update firmware regularly.

Advertisements
News Desk

News Desk

Welcome to our web desk! We're a dedicated team of digital enthusiasts passionate about delivering timely and engaging content to our online audience.

Related Posts

WeRide and Lenovo Collaborate to Deploy 200,000 Autonomous Vehicles Globally Over Five Years
Business

WeRide and Lenovo Collaborate to Deploy 200,000 Autonomous Vehicles Globally Over Five Years

April 27, 2026
Mian Zahid Hussain with Governor Balochistan, Chinese Consul General Yang Yundong, S. M. Tanveer,
Business

Mian Zahid Hussain with Governor Balochistan, Chinese Consul General Yang Yundong, S. M. Tanveer,

April 27, 2026
BingX TradFi Elevates with TradingView, Bringing Pro-Grade Analysis to Multi-Asset Trading
Business

BingX TradFi Elevates with TradingView, Bringing Pro-Grade Analysis to Multi-Asset Trading

April 27, 2026
Trump Praises Pakistan’s Role in Peace Efforts, Reaffirms Stance on Iran Nuclear Talks
Headline

Trump Praises Pakistan’s Role in Peace Efforts, Reaffirms Stance on Iran Nuclear Talks

April 26, 2026
Palestinians Vote in Limited Municipal Elections in West Bank and Gaza Amid War Aftermath and Political Stagnation
WORLD

Palestinians Vote in Limited Municipal Elections in West Bank and Gaza Amid War Aftermath and Political Stagnation

April 25, 2026
America also reveals the ability to hear sounds in plant.
HEALTH / EDUCATION

America also reveals the ability to hear sounds in plant.

April 24, 2026
India’s ‘8-sided’ Quran is the center of attention at Mecca Museum.
HEALTH / EDUCATION

India’s ‘8-sided’ Quran is the center of attention at Mecca Museum.

April 24, 2026
US Weighs NATO Measures Over Iran War Support, Including Suspension Options for Spain: Report
WORLD

US Weighs NATO Measures Over Iran War Support, Including Suspension Options for Spain: Report

April 24, 2026
Abbott: HPD must implement new Houston ICE policy ‘in the next 24 hours’
HEALTH / EDUCATION

Abbott: HPD must implement new Houston ICE policy ‘in the next 24 hours’

April 24, 2026
A very common habit that causes constipation.
HEALTH / EDUCATION

A very common habit that causes constipation.

April 24, 2026
Next Post
Grand Celebration: Russia Day at Friendship House

Grand Celebration: Russia Day at Friendship House

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Popular

Indus Motor Company declares profit after tax of PKR 5.1 billion.

KP Power Reset: Bureaucratic Empire Shaken at the Top. 

Malik Khuda Bakhsh Meeting Between Humayun Khan, Additional Secretary NEECA on EV Charging Stations

Karachi Receives Widespread Rainfall as Authorities Issue High Alert

Murtaza Wahab Inaugurates Recycled Plastic Road by English Biscuit Manufacturers in Karachi

Must Read

Flag Hoisting Ceremony hosted on Independence Day of Pakistan in Belarus
PAKISTAN

Flag Hoisting Ceremony hosted on Independence Day of Pakistan in Belarus

August 15, 2022
People impacted by ongoing LPG price rises.
Headline

People impacted by ongoing LPG price rises.

December 3, 2023
The Azb is a 24/7 online news platform that covers a wide range of topics including business, economics, technology, finance, travel, fashion, and lifestyle.

Quick Links

  • Home
  • About us
  • SCI-TECH
  • Live TV
  • Banking

Useful Links

  • Videos
  • Reviews
  • Advertorial
  • Photos
  • About us
  • Author
  • Home
  • Latest News
  • Partner
  • Privacy Policy
  • Russian Theatre Group Celebrates Fifth Anniversary in Pakistan.
  • Terms and Conditions
  • The Azb – More Than Just News
  • Contact

© Copyright 2024 theazb. All Rights Reserved.

No Result
View All Result
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION

© Copyright 2024 theazb. All Rights Reserved.