Unauthorized Password Reset Vulnerability in ZKTeco BioTime by ZKTeco
CVE-2023-38949
7.5HIGH
What is CVE-2023-38949?
A security misconfiguration in the ZKTeco BioTime version 8.5.5 exposes a hidden API, allowing attackers without authentication to reset the Administrator password through specially crafted web requests. This vulnerability poses significant risks to the integrity of system access and data security, making it essential for users to apply corrective measures promptly. For further details and mitigation strategies, refer to the official resources provided by ZKTeco and security researchers.