CVE-2023-38949: ZKTeco BioTime

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.

Affected products

  • ZKTeco BioTime: version 8.5.5 only

Published 2023-08-03. Last modified 2026-07-09.