VYPR
Unrated severityNVD Advisory· Published May 22, 2014· Updated May 6, 2026

CVE-2014-2938

CVE-2014-2938

Description

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.

Affected products

8
  • Hanon/Faceid4 versions
    cpe:2.3:h:hanon:faceid:f710:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:h:hanon:faceid:f710:*:*:*:*:*:*:*
    • cpe:2.3:h:hanon:faceid:f810:*:*:*:*:*:*:*
    • cpe:2.3:h:hanon:faceid:fa007:*:*:*:*:*:*:*
    • cpe:2.3:h:hanon:faceid:fk800:*:*:*:*:*:*:*
  • cpe:2.3:o:hanon:faceid_f710_firmware:1.007.109:*:*:*:*:*:*:*
  • cpe:2.3:o:hanon:faceid_f810_firmware:*:*:*:*:*:*:*:*
    Range: <=1.007.109
  • cpe:2.3:o:hanon:faceid_fa007_firmware:*:*:*:*:*:*:*:*
    Range: <=1.007.109
  • cpe:2.3:o:hanon:faceid_fk800_firmware:*:*:*:*:*:*:*:*
    Range: <=1.007.109

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.