CVE-2023-38950
ZKTeco BioTime Path Traversal Vulnerability
Record summary
CVE-2023-38950 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template. CISA lists CVE-2023-38950 in KEV.
Description
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 19, 2025 · CISA
- VulnCheck KEV
- Listed · May 2, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BioTimeBrowse ZKTeco / BioTime | CISA | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHZKTeco BioTime v8.5.5 - Path TraversalCVSS 7.5
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Impact
Unauthenticated attackers can read arbitrary files from the server through path traversal in the iclock API url parameter, potentially exposing employee biometric data, attendance records, and system credentials.
Remediation
Update ZKTeco BioTime to a version newer than 8.5.5 that validates file paths in the iclock API and restricts access to authorized files only.
Source: ProjectDiscovery