Vulnerability CVE-2023-38949


Published: 2023-08-03   Modified: 2023-08-04

Description:
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.

 References:
http://zkteco.com
https://claroty.com/team82/disclosure-dashboard/cve-2023-38949

Copyright 2026, cxsecurity.com

 

Back to Top