CVE-2023-3941 is a critical relative path traversal vulnerability affecting ZkTeco-based OEM devices, including specific models like ZkTeco ProFace X and Smartec ST-FR043, running firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 and potentially others. This flaw allows an unauthenticated attacker to write arbitrary files to the system with root privileges over the network, as indicated by its CVSS score of 10.0. While there is no known public exploit code or active exploitation listed in KEV, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ZkTeco | ZkTeco-Based OEM Devices With Firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 | ZAM170-NF-1.8.25-7354-Ver1.0.0CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.