VYPR

Vendor CVEs

Zkteco

All CVEs

66 total · sorted by risk
  • CVE-2022-38801MedNov 30, 2022
    risk 0.35cvss 5.4epss 0.00

    In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.

  • CVE-2022-30515MedNov 8, 2022
    risk 0.35cvss 5.3epss 0.01

    ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

  • CVE-2025-15128MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_setting/ of the component Endpoint. Performing a manipulation of the argument backup_encryption_password_decrypt/export_encryption_password_decrypt results…

  • CVE-2025-55280MedAug 13, 2025
    risk 0.34cvss epss 0.00

    This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary…

  • CVE-2023-38958MedAug 3, 2023
    risk 0.34cvss 5.3epss 0.00

    An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.

  • CVE-2022-44213MedDec 9, 2022
    risk 0.31cvss 4.8epss 0.00

    ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-3938MedMay 21, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM devices allows an attacker to authenticate under any user from the device database. This issue affects  ZkTeco-based OEM devices (ZkTeco ProFace X,…

  • CVE-2016-20028MedMar 16, 2026
    risk 0.28cvss 4.3epss 0.00

    ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add superadmin accounts without validity…

  • CVE-2024-45250MedOct 6, 2024
    risk 0.28cvss 4.3epss 0.00

    ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

  • CVE-2024-2318MedMar 8, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input…

  • CVE-2024-11049LowNov 10, 2024
    risk 0.24cvss 3.7epss 0.00

    A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The…

  • CVE-2024-6523LowJul 5, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add Handler. The manipulation of the argument user with the input leads to cross site…

  • CVE-2024-6006LowJun 15, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The…

  • CVE-2024-6005LowJun 15, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting.…

  • CVE-2024-1706LowFeb 21, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input hi causes cross site scripting. Remote exploitation of the attack is possible. The…

  • CVE-2024-6344LowJun 26, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to…

Page 2 of 2