VendorsZKTecobiotimeany version
Vulnerabilities

ZKTeco BioTime any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-38950
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Published 2023-08-03 · Analyzed
7.5KEVEPSS 0.925
CVE-2024-13966
ZKTeco BioTime default password
Published 2025-05-27 · Analyzed
7.3EPSS 0.004
CVE-2022-38803
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDF
Published 2022-11-30 · Modified
6.8EPSS 0.006
CVE-2022-38802
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by exploiting XSS into a pdf generator when exporting data as a PDF
Published 2022-11-30 · Modified
6.2EPSS 0.006
CVE-2024-6523
ZKTeco BioTime system-group-add cross site scripting
Published 2024-07-05 · Modified
5.4EPSS 0.005
CVE-2022-38801
In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.
Published 2022-11-30 · Modified
5.4EPSS 0.003