Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zkteco

First CVE: Sep 21, 2017Active for: 9 yearsTotal CVEs: 44
51.8
VTI Score
TOP TARGET

Zkteco manufactures a focused portfolio of biometric access-control and time-and-attendance systems, including products such as BioTime, ZKBio CVSecurity, and BioaccessIVS, that are widely deployed in enterprises for physical and logical access management. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the attractive target profile of internet-exposed authentication and identity infrastructure. The exposure recurs through application-layer and access-control weakness classes—cross-site scripting, path traversal, code injection, authorization bypass, and cross-site request forgery—that are characteristic of web-facing credential and permission-enforcement systems. Defenders should treat this vendor's advisories as high-priority for internet-reachable deployments and implement strict network segmentation around biometric and access-control appliances; current severity, exploitation activity, and affected product coverage are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
2.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zkteco over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
May 27, 2025
423 days ago

Products(35 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38950HIGH
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerabili
Aug 3, 20237.596YESYES
CVE-2022-36635HIGH
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
Oct 7, 20228.839NONO
CVE-2022-42953HIGH
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=
Dec 25, 20227.537NOYES
CVE-2017-13129HIGH
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that
Sep 26, 20178.035NOYES
CVE-2017-14680HIGH
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
Sep 21, 20177.535NOYES
CVE-2023-38952HIGH
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type
Aug 3, 20237.534NOYES
CVE-2022-36634HIGH
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
Oct 7, 20228.831NONO
CVE-2020-17474CRITICAL
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators
Aug 14, 20209.830NONO
CVE-2023-38951CRITICAL
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sft
Aug 3, 20239.829NONO
CVE-2017-17056HIGH
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component
Dec 4, 20178.828NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
9%
34%
43%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.3%)
Network43 (97.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (95.5%)
High2 (4.5%)
Unknown0 (0.0%)
User Interaction
None30 (68.2%)
Unknown0 (0.0%)
Required14 (31.8%)
Privileges Required
Low16 (36.4%)
High3 (6.8%)
None25 (56.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
1 CVE
2.3% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.5% of CVEs· 95th percentile
ExploitDB
3 CVEs
6.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zkteco.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zkteco — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zkteco's Products

View all 4 CNAs →

Top CWEs