Loading
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Use Zkteco vendor hub and Biotime product page to widen CVE-2023-38949 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-38950, CVE-2023-38951 and CVE-2023-51142 for nearby disclosures in the same product family.