Skip to main content

Vendor/product archive

zkteco / biotime CVEs

Beta · best-effort

12 CVEs tagged to zkteco / biotime1 Critical, 4 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-13966

Published May 27, 2025

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6523

Published Jul 5, 2024

A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add Handler. The mani…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51142

Published Apr 11, 2024

An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51141

Published Apr 11, 2024

An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38952

Published Aug 3, 2023

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38951

Published Aug 3, 2023

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sf…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38950

Published Aug 3, 2023

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerabil…

CVSS 7.5 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-38949

Published Aug 3, 2023

An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38803

Published Nov 30, 2022

Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting X…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38802

Published Nov 30, 2022

Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38801

Published Nov 30, 2022

In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30515

Published Nov 8, 2022

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1