Loading
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").
Use CWE-1393, Zkteco vendor hub and Biotime product page to widen CVE-2024-13966 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-38950, CVE-2023-38951 and CVE-2023-51142 for nearby disclosures in the same product family.