Known Vulnerabilities for products from ZKTeco
Listed below are 20 of the newest known vulnerabilities associated with the vendor "ZKTeco".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by ZKTeco can be found at device.report : ZKTeco
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-8598 json | Not Provided | 2026-05-20 | 2026-05-20 | |
| CVE-2024-6344 json | A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unkno... | Not Provided | 2024-06-26 | 2026-04-29 |
| CVE-2024-6006 json | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is... | Not Provided | 2024-06-15 | 2026-04-29 |
| CVE-2024-6005 json | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulne... | Not Provided | 2024-06-15 | 2026-04-29 |
| CVE-2024-2318 json | A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is... | Not Provided | 2024-03-08 | 2026-04-29 |
| CVE-2024-1706 json | A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Depa... | Not Provided | 2024-02-21 | 2026-04-29 |
| CVE-2023-38958 json | An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doo... | 5.3 - MEDIUM | 2023-08-03 | 2023-08-08 |
| CVE-2023-38956 json | A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via su... | 7.5 - HIGH | 2023-08-03 | 2023-08-07 |
| CVE-2023-38955 json | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, inclu... | 7.5 - HIGH | 2023-08-03 | 2023-08-07 |
| CVE-2023-38954 json | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. | 9.8 - CRITICAL | 2023-08-03 | 2023-08-07 |
| CVE-2023-38952 json | Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read sensitive backup files and access s... | 7.5 - HIGH | 2023-08-03 | 2023-08-08 |
| CVE-2023-38951 json | A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows attackers to write arbitrary files via using a malicious SFTP ... | 9.8 - CRITICAL | 2023-08-03 | 2023-08-08 |
| CVE-2023-38950 json | A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary ... | 7.5 - HIGH | 2023-08-03 | 2023-08-08 |
| CVE-2023-38949 json | An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator pas... | 7.5 - HIGH | 2023-08-03 | 2023-08-08 |
| CVE-2023-4587 json | ** UNSUPPPORTED WHEN ASSIGNED ** An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This v... | 5.5 - MEDIUM | 2023-09-04 | 2023-11-07 |
| CVE-2022-44213 json | ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS). | 4.8 - MEDIUM | 2022-12-09 | 2022-12-12 |
| CVE-2022-42953 json | Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct reques... | 7.5 - HIGH | 2022-12-25 | 2023-08-08 |
| CVE-2022-38803 json | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authe... | 6.8 - MEDIUM | 2022-11-30 | 2022-12-02 |
| CVE-2022-38802 json | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, ... | 6.2 - MEDIUM | 2022-11-30 | 2022-12-02 |
| CVE-2022-38801 json | In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-s... | 5.4 - MEDIUM | 2022-11-30 | 2022-12-02 |
Known software with vulnerabilities from ZKTeco
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Zkteco | Facedepot 7b | - |
| Operating System | Zkteco | Facedepot 7b Firmware | 1.0.213 |
| Application | Zkteco | Zkbiosecurity Server | 1.0.0_20190723 |
| Application | Zkteco | Zktime Web | 2.0.1.12280 |