Known Vulnerabilities for BioTime by ZKTeco

Listed below are 10 of the newest known vulnerabilities associated with "BioTime" by "ZKTeco".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-15128 json A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_s... Not Provided 2025-12-28 2026-06-11
CVE-2023-51142 json An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. Not Provided 2024-04-11 2026-07-09
CVE-2023-51141 json An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication... Not Provided 2024-04-11 2026-07-09
CVE-2023-38952 json Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to th... Not Provided 2023-08-03 2026-07-09
CVE-2023-38951 json ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrar... Not Provided 2023-08-03 2026-07-09
CVE-2023-38950 json A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary ... Not Provided 2023-08-03 2026-07-09
CVE-2023-38949 json An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator pas... Not Provided 2023-08-03 2026-07-09
CVE-2022-38803 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authe... 6.8 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38802 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, ... 6.2 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38801 json In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-s... 5.4 - MEDIUM 2022-11-30 2022-12-02

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report