CVE-2023-38029: Saho Adm-100 Firmware
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.
Affected products
- Saho Adm-100 Firmware: version 0.0.4.0 only; version 0.0.4.3 only; version 0.0.4.6 only; version 0.0.4.8 only; version q20100602 only; version t190 only; …
- Saho Adm-100fp Firmware: version q20100602 only; version t190 only; version t17041702 only; version t18051803 only
Published 2023-08-28. Last modified 2026-06-17.