Attackers Can Authenticate Under Any User in ZkTeco Devices Due to SQL Injection Vulnerability
CVE-2023-3938
What is CVE-2023-3938?
A vulnerability exists in ZkTeco-based OEM devices that allows attackers to exploit improper handling of special elements in SQL commands, resulting in the potential for unauthorized access to user accounts within the device database. This flaw specifically impacts devices such as the ZkTeco ProFace X and Smartec ST-FR043, among others, particularly those operating on the ZAM170-NF-1.8.25-7354-Ver1.0.0 version and similar. Hackers can manipulate SQL queries to authenticate as any user, posing significant security risks to organizations utilizing these devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 ZAM170-NF-1.8.25-7354-Ver1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
