CVE-2023-38030: Saho Adm-100 Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

Affected products

  • Saho Adm-100 Firmware: version 0.0.4.0 only; version 0.0.4.3 only; version 0.0.4.6 only; version 0.0.4.8 only; version q20100602 only; version t190 only; …
  • Saho Adm-100fp Firmware: version q20100602 only; version t190 only; version t17041702 only; version t18051803 only

Published 2023-08-28. Last modified 2026-06-17.