ZeroHour

Vulnerabilities

44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13966
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'.

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

NVD description · AI analysis pending
6.9<1%
  • zkteco biotime
CVE-2025-45746
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console.

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.

NVD description · AI analysis pending
9.8<1% PoC
  • zkteco zkbio cvsecurity
CVE-2024-11049
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1.

A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.3<1%
  • zkteco zkbio time
CVE-2023-51157
Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • zkteco wdms
CVE-2024-36526
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

NVD description · AI analysis pending
9.8<1% PoC
  • zkteco zkbio cvsecurity
CVE-2024-6523
A vulnerability was found in ZKTeco BioTime up to 9.5.2.

A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add Handler. The manipulation of the argument user with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-270366 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • zkteco biotime
CVE-2024-6344
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0.

A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. The vendor explains, that "[s]ince ZKBio CVSecurity v5000 has been withdrawn from the market, we recommend upgrading to ZKBio CVSecurity V6600 6.1.3_R or above". This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
1.9<1%
  • zkteco zkbiosecurity v5000
CVE-2024-6006
+1 in the same advisory: …6005
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0.

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor explains, "that ZKBio Security V5000 has been withdrawn from the market and [is] recommended for upgrading to the ZKBio CVSecurity latest version." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
2.0<1% PoC
  • zkteco zkbiosecurity v5000
CVE-2024-35430
In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.

In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.

NVD description · AI analysis pending
8.1
group max
<1% PoC
  • zkteco zkbio cvsecurity
CVE-2023-51142
+1 in the same advisory: …51141
An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • zkteco biotime
CVE-2024-2318
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028.

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input ../../../../zkbio_media.sql leads to path traversal: '../filedir'. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.3 Build 2025-05-26-1605 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
2.1<1%
  • zkteco zkbio media
CVE-2024-22988
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.

NVD description · AI analysis pending
9.8<1%
  • zkteco zkbio wdms
CVE-2024-1706
A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2.

A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input hi causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor explains: "ZKBio Access IVS is no longer maintained and the product has been replaced by ZKBio CVAccess, it is recommended to replace it with the latest version of ZKBio CVAccess." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
2.0<1%
  • zkteco zkbio access ivs
CVE-2023-4587
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60.

An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered user backup files or device configuration files over a local network or through a VPN server.

NVD description · AI analysis pending
5.5<1%
  • zkteco zem800 firmware
CVE-2023-38950
+3 in the same advisory: …38951 …38952 …38949
Unauthenticated Path Traversal in ZKTeco BioTime iclock API (Arbitrary File Read)

CVE-2023-38950 is a path traversal flaw (CWE-22) in the iclock API of ZKTeco BioTime, confirmed in version 8.5.5, that lets an attacker send a crafted traversal payload to the API endpoint without any authentication. An unauthenticated remote attacker who exploits it gains the ability to read arbitrary files on the BioTime server, with high confidentiality impact but no integrity or availability impact, per the CVSS 7.5 vector. Organizations running affected BioTime deployments, particularly time-and-attendance servers reachable from the internet, are exposed. The flaw has a public proof-of-concept reference, a very high EPSS score of 84.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-19, indicating confirmed exploitation in the wild. CISA's required action is to apply vendor mitigations (follow BOD 22-01 guidance for cloud services) or discontinue use of the product if mitigations are unavailable.

Do: Upgrade ZKBioTime to version 9.0.120240617.19506 or later, per the vendor fix. If upgrading is not immediately possible, restrict internet exposure of the iclock API (firewall or reverse proxy) and check logs for unauthenticated requests containing traversal sequences to the endpoint; given CISA's required action for KEV entries, apply mitigations per vendor instructions or discontinue use. Since the flaw allows arbitrary file reads, review whether configuration files or credentials on the BioTime server were reachable and rotate exposed secrets as a precaution.

7.5
group max
85% KEV PoC
  • zkteco biotime 8.5.5 confirmed affected; fixed in ZKBioTime 9.0.120240617.19506
moderateroughly thousands (1k-10k) of exposed BioTime servers; total install base unknown
CVE-2023-38954
+3 in the same advisory: …38956 …38955 …38958
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

NVD description · AI analysis pending
9.8
group max
<1%
  • zkteco bioaccess ivs
CVE-2022-42953
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

NVD description · AI analysis pending
7.55% PoC ×2
  • zkteco zmm200 firmware
  • zkteco zmm210 firmware
  • zkteco zmm220 firmware
  • +1 more
CVE-2022-44213
ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

NVD description · AI analysis pending
4.8<1% PoC
  • zkteco automatic data master server
CVE-2021-39434
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200

A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.

NVD description · AI analysis pending
7.5<1%
  • zkteco zktime
CVE-2022-38803
+2 in the same advisory: …38802 …38801
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log.

Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDF

NVD description · AI analysis pending
6.8
group max
<1% PoC
  • zkteco biotime
CVE-2022-30515
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

NVD description · AI analysis pending
5.3<1% PoC
  • zkteco biotime
CVE-2022-36635
+1 in the same advisory: …36634
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

NVD description · AI analysis pending
8.817% PoC
  • zkteco zkbiosecurity v5000
CVE-2020-17474
+1 in the same advisory: …17473
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate use

A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • zkteco zkbiosecurity server
  • zkteco facedepot 7b firmware
CVE-2017-17056
+1 in the same advisory: …17057
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modif

The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI. An attacker takes advantage of this scenario and creates a crafted CSRF link to add himself as an administrator to the ZKTime Web Software. He then uses social engineering methods to trick the administrator into clicking the forged HTTP request. The request is executed and the attacker becomes the Administrator of the ZKTime Web Software. If the vulnerability is successfully exploited, then an attacker (who would be a normal user of the web application) can escalate his privileges and become the administrator of ZKTime Web Software.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • zkteco zktime web
CVE-2017-13129
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrator

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

NVD description · AI analysis pending
8.01%
  • zkteco zktime web
CVE-2017-14680
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

NVD description · AI analysis pending
7.54% PoC ×2
  • zkteco zktime web