Known Vulnerabilities for Biotime by Zkteco

Listed below are 8 of the newest known vulnerabilities associated with "Biotime" by "Zkteco".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-15128 json A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_s... Not Provided 2025-12-28 2026-06-11
CVE-2023-38952 json Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read sensitive backup files and access s... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2023-38951 json A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows attackers to write arbitrary files via using a malicious SFTP ... 9.8 - CRITICAL 2023-08-03 2023-08-08
CVE-2023-38950 json A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary ... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2023-38949 json An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator pas... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2022-38803 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authe... 6.8 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38802 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, ... 6.2 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38801 json In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-s... 5.4 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-30515 json ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them throu... 5.3 - MEDIUM 2022-11-08 2022-11-09
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report