S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2023-38950 Scanner

CVE-2023-38950 Scanner - Path Traversal vulnerability in ZKTeco BioTime

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-38950
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ZKTeco BioTime is an advanced time management software used widely across various sectors for efficient workforce management. Developed by ZKTeco, it is designed to facilitate biometric verification and attendance management. Organizations from small businesses to large enterprises implement this software to enhance security control and attendance accuracy. With its scalable deployment, BioTime is utilized both locally and internationally, adapting to various time-attendance needs. The software plays a significant role in efficient workforce administration by automating attendance tracking and monitoring. Moreover, the comprehensive integrations make it versatile in various operational scenarios.

The Path Traversal vulnerability in ZKTeco BioTime v8.5.5 allows an attacker to read arbitrary files from the server. This vulnerability, identified as CVE-2023-38950, arises due to insufficient input validation in the iclock API. As a result, unauthenticated attackers can gain unauthorized access to sensitive data. Exploiting the flaw could lead to data leakage and potential exposure of critical system files. Path Traversal is particularly critical as it might facilitate subsequent steps of an attack, such as system manipulation or code injection. Organizations using this software need to be aware of this severe vulnerability.

The technical root of the vulnerability lies in the request handling method wherein the application fails to sanitize user-supplied input properly. The vulnerability is centered in the iclock API, specifically when crafted payloads are supplied to the iclock/file endpoint. By using relative path traversal sequences, an attacker can access files outside the intended directories. The crafted requests exploit flaws in URL parameter processing, enabling file reading operations across unauthorized paths. This vulnerability potentially allows the exposure of system files integral to application operation.

Successful exploitation of the Path Traversal vulnerability could have severe consequences. It could lead to unauthorized access to sensitive configuration files, user data, and other critical information stored on the server. Attackers could leverage this information to mount further attacks against the application or the server. Potential information disclosure might include system credentials, leading to broader system compromises. Additionally, having access to the server’s content could facilitate privilege escalation attacks.

REFERENCES

Solution Advice
  • Update to a patched version of ZKTeco BioTime that addresses this vulnerability.
  • Implement strict input validation on the URL parameter to prevent path traversal sequences.
  • Use firewall rules to restrict access to the iclock API endpoints to trusted users only.
  • Regularly review the application logs for unusual access patterns.
  • Consider implementing security solutions that monitor and block path traversal attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.