ZkTeco Relative Path Traversal Vulnerability Affects Multiple Devices
CVE-2023-3940
What is CVE-2023-3940?
A relative path traversal vulnerability exists in ZkTeco-based OEM devices, permitting attackers to access arbitrary files on the system. This vulnerability potentially exposes sensitive data and compromises the security integrity of the device. Affected models primarily include ZkTeco ProFace X and various Smartec devices, particularly those using specific firmware versions such as ZAM170-NF-1.8.25-7354-Ver1.0.0. Proper security measures should be implemented to mitigate risks associated with unauthorized file access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 ZAM170-NF-1.8.25-7354-Ver1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
