S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 17, 2025

CVE-2023-38952 Scanner

CVE-2023-38952 Scanner - Privilege Escalation vulnerability in ZKTeco BioTime

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-38952
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ZKTeco's BioTime is a time attendance software widely used by organizations to monitor and manage employee time records. It allows for the storage and analysis of attendance data, helping companies to streamline their human resource operations. BioTime supports various attendance-related applications, providing both administrators and employees with an interface for managing work schedules and reports. The software is particularly beneficial for companies that require precise attendance tracking and time management functionalities. It integrates with biometric devices, enhancing the accuracy of timekeeping and attendance data. Organizations ranging from small enterprises to large institutions utilize ZKTeco BioTime for its comprehensive attendance management features.

The privilege escalation vulnerability in ZKTeco BioTime allows users with default employee credentials to gain unauthorized administrative access. This vulnerability arises from the lack of role validation in user sessions, making it possible for attackers to perform actions typically reserved for admin users. By exploiting this flaw, unauthorized users can access sensitive system parts, potentially compromising the security of the entire application and any associated data. The inherent risk lies in the software not restricting session roles, leading to inadequate access control measures. Such vulnerabilities can result in unauthorized data access and modifications, severely affecting system integrity.

The vulnerability in ZKTeco BioTime is technically rooted in its session management and authentication mechanisms. Attackers can utilize default credentials to log in as employees, as the system does not require session role validation to restrict administrative functions. Endpoints like '/login/' and '/base/dbbackuplog/table/' can be exploited, with credentials sent via POST requests, bypassing typical security controls. Vulnerable parameters include 'username' and 'password', which when combined with a clusterbomb attack pattern, further expose the system to unauthorized data exposure and potential misuse. This lack of robust authentication oversight leaves critical system elements open to exploitation.

Exploiting this vulnerability can lead to significant unauthorized administrative activity, data breaches, and system compromise. Malicious actors could manipulate or extract sensitive data, such as backup files, potentially leading to significant financial or reputational loss for the organization. Moreover, privileged access could allow attackers to alter system configurations or disrupt operations, affecting organizational productivity. The potential unauthorized disclosure of sensitive company data could also infringe on privacy regulations, resulting in legal implications. Overall, exploiting this privilege escalation can have severe implications for both system security and organizational compliance.

REFERENCES

Solution Advice
  • Restrict the use of default credentials and enforce strong password policies across all user accounts.
  • Implement rigorous session role validation to ensure that users only have access to features pertinent to their access level.
  • Regularly update the BioTime software to the latest version to incorporate improved security features and patches.
  • Conduct periodic audits of user accounts to identify any unauthorized access attempts and improve overall access control mechanisms.
  • Train employees on security best practices to mitigate the risks associated with weak or default credential usage.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-38952 Scanner - Privilege Escalation vulnerability in ZKTeco BioTime | S4E