← Back

Zkteco

zkteco

44 CVEs • 35 products

Products (35)

Click to collapse
Toggle
Biotime
biotime
Zktime Web
zktime_web
Bioaccess Ivs
bioaccess_ivs
Zktime
zktime
Zkbio Wdms
zkbio_wdms
Zkbio Media
zkbio_media
Wdms
wdms
Zkbio Time
zkbio_time
Facedepot 7b
facedepot_7b
Zmm200
zmm200
Zmm210
zmm210
Zmm220
zmm220
Zem720
zem720
Zem600
zem600
Zem800
zem800
Zem510
zem510
Zem560
zem560
Zem760
zem760
Zem500
zem500

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zkteco
1Zem800 Firmware
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered user backup files or device configuration files over a local network o...Show more
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered user backup files or device configuration files over a local network or through a VPN server.Show less
1Zkteco
1Biotime
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by def...Show more
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.Show less
1Zkteco
1Biotime
Jul 9, 2026
Aug 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path tr...Show more
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.Show less
1Zkteco
1Biotime
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19...Show more
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.Show less
1Zkteco
1Biotime
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
1Zkteco
1Bioaccess Ivs
Jul 9, 2026
Aug 3, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
1Zkteco
1Bioaccess Ivs
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
1Zkteco
1Bioaccess Ivs
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
1Zkteco
1Bioaccess Ivs
Jul 9, 2026
Aug 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
1Zkteco
10Zem500 Firmware
Zem510 FirmwareZem560 Firmware+7 more
Jun 17, 2026
Dec 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be bef...Show more
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).Show less
1Zkteco
1Automatic Data Master Server
Jun 17, 2026
Dec 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).
1Zkteco
1Zktime
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
1Zkteco
1Biotime
Jun 17, 2026
Nov 30, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting da...Show more
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDFShow less
1Zkteco
1Biotime
Jun 17, 2026
Nov 30, 2022
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by ex...Show more
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by exploiting XSS into a pdf generator when exporting data as a PDFShow less
1Zkteco
1Biotime
Jun 17, 2026
Nov 30, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.
1Zkteco
1Biotime
Jun 17, 2026
Nov 8, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
1Zkteco
1Zkbiosecurity V5000
Jul 9, 2026
Oct 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
1Zkteco
1Zkbiosecurity V5000
Jul 9, 2026
Oct 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
1Zkteco
2Facedepot 7b Firmware
Zkbiosecurity Server
Jun 17, 2026
Aug 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces...Show more
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.Show less
1Zkteco
2Facedepot 7b Firmware
Zkbiosecurity Server
Jun 17, 2026
Aug 14, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.