CVE-2014-2938: Hanon Faceid

High severity, CVSS 8.3. EPSS: 1.6% chance of exploitation in the next 30 days.

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.

Affected products

  • Hanon Faceid
  • Hanon Faceid f710 Firmware: version 1.007.109 only
  • Hanon Faceid f810 Firmware: up to and including 1.007.109
  • Hanon Faceid FA007 Firmware: up to and including 1.007.109
  • Hanon Faceid FK800 Firmware: up to and including 1.007.109

Published 2014-05-22. Last modified 2026-06-17.