Zkteco manufactures a focused portfolio of biometric access-control and time-and-attendance systems, including products such as BioTime, ZKBio CVSecurity, and BioaccessIVS, that are widely deployed in enterprises for physical and logical access management. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the attractive target profile of internet-exposed authentication and identity infrastructure. The exposure recurs through application-layer and access-control weakness classes—cross-site scripting, path traversal, code injection, authorization bypass, and cross-site request forgery—that are characteristic of web-facing credential and permission-enforcement systems. Defenders should treat this vendor's advisories as high-priority for internet-reachable deployments and implement strict network segmentation around biometric and access-control appliances; current severity, exploitation activity, and affected product coverage are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zkteco over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38950HIGH A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerabili | Aug 3, 2023 | 7.5 | 96 | YES | YES |
CVE-2022-36635HIGH ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. | Oct 7, 2022 | 8.8 | 39 | NO | NO |
CVE-2022-42953HIGH Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style= | Dec 25, 2022 | 7.5 | 37 | NO | YES |
CVE-2017-13129HIGH Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that | Sep 26, 2017 | 8.0 | 35 | NO | YES |
CVE-2017-14680HIGH ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document. | Sep 21, 2017 | 7.5 | 35 | NO | YES |
CVE-2023-38952HIGH Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type | Aug 3, 2023 | 7.5 | 34 | NO | YES |
CVE-2022-36634HIGH An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request. | Oct 7, 2022 | 8.8 | 31 | NO | NO |
CVE-2020-17474CRITICAL A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators | Aug 14, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-38951CRITICAL ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sft | Aug 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2017-17056HIGH The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component | Dec 4, 2017 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zkteco.
Media articles that mention a CVE ID that affects a product developed by Zkteco — matched by CVE ID, not by vendor name.