CVE-2014-2938: Hanon Faceid
High severity, CVSS 8.3. EPSS: 1.6% chance of exploitation in the next 30 days.
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
Affected products
- Hanon Faceid
- Hanon Faceid f710 Firmware: version 1.007.109 only
- Hanon Faceid f810 Firmware: up to and including 1.007.109
- Hanon Faceid FA007 Firmware: up to and including 1.007.109
- Hanon Faceid FK800 Firmware: up to and including 1.007.109
Published 2014-05-22. Last modified 2026-06-17.