CVE-2022-30515

MEDIUM

ZKTeco BioTime 8.5.4 - Unauthenticated Employee Photo Exposure via Filename Enumeration

Title source: llm
STIX 2.1

Description

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://codingkoala.eu/posts/CVE202230515/
Product, Vendor Advisory
https://www.zkteco.me/software-5

Scores

CVSS v3 5.3
EPSS 0.0067
EPSS Percentile 47.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
zkteco/biotime 8.5.4
zkteco/biotime 8.5.5
Published Nov 08, 2022
Tracked Since Feb 18, 2026