Known Vulnerabilities for products from Zkteco

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Zkteco".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Zkteco can be found at device.report : Zkteco

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-8598 json Not Provided 2026-05-20 2026-05-20
CVE-2024-6344 json A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unkno... Not Provided 2024-06-26 2026-04-29
CVE-2024-6006 json A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is... Not Provided 2024-06-15 2026-04-29
CVE-2024-6005 json A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulne... Not Provided 2024-06-15 2026-04-29
CVE-2024-2318 json A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is... Not Provided 2024-03-08 2026-04-29
CVE-2024-1706 json A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Depa... Not Provided 2024-02-21 2026-04-29
CVE-2023-38958 json An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doo... 5.3 - MEDIUM 2023-08-03 2023-08-08
CVE-2023-38956 json A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via su... 7.5 - HIGH 2023-08-03 2023-08-07
CVE-2023-38955 json ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, inclu... 7.5 - HIGH 2023-08-03 2023-08-07
CVE-2023-38954 json ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. 9.8 - CRITICAL 2023-08-03 2023-08-07
CVE-2023-38952 json Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read sensitive backup files and access s... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2023-38951 json A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows attackers to write arbitrary files via using a malicious SFTP ... 9.8 - CRITICAL 2023-08-03 2023-08-08
CVE-2023-38950 json A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary ... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2023-38949 json An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator pas... 7.5 - HIGH 2023-08-03 2023-08-08
CVE-2023-4587 json ** UNSUPPPORTED WHEN ASSIGNED ** An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This v... 5.5 - MEDIUM 2023-09-04 2023-11-07
CVE-2022-44213 json ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS). 4.8 - MEDIUM 2022-12-09 2022-12-12
CVE-2022-42953 json Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct reques... 7.5 - HIGH 2022-12-25 2023-08-08
CVE-2022-38803 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authe... 6.8 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38802 json Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, ... 6.2 - MEDIUM 2022-11-30 2022-12-02
CVE-2022-38801 json In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-s... 5.4 - MEDIUM 2022-11-30 2022-12-02

Known software with vulnerabilities from Zkteco

Type Vendor Product Version
HardwareZktecoFacedepot 7b-
Operating
System
ZktecoFacedepot 7b Firmware1.0.213
ApplicationZktecoZkbiosecurity Server1.0.0_20190723
ApplicationZktecoZktime Web2.0.1.12280
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report