Junglewise Threat Intelligence

CVE-2023-38950: ZKTeco BioTime path traversal in iclock API

CVE-2023-38950 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-05-19

Vendors: Zkteco.

Executive brief

ZKTeco BioTime is a web-based time and attendance management software used to track employee hours and attendance. A security flaw in this system allows unauthorized individuals to access sensitive files stored on the server without needing a username or password. This could lead to the exposure of configuration files, system credentials, or other private data, and the vulnerability is known to be actively exploited by attackers.

Technical details

A path traversal vulnerability (CWE-22) exists in the iclock API component of ZKTeco BioTime. The root cause is improper validation of user-supplied input in API requests, which allows an attacker to use directory traversal sequences (e.g., ../) to escape the intended directory. An unauthenticated, remote attacker can exploit this by sending a specially crafted network request to the iclock API to read arbitrary files on the underlying operating system. This vulnerability has been observed in active exploitation. A fix is available in ZKBioTime version 9.0.120240617.19506.

Affected products

  • ZKTeco BioTime 8.5.5 and versions prior to 9.0.120240617.19506

Timeline

  • 2023-08-03: disclosed: Initial NVD publication
  • 2025-05-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2024-06-17: patched: Fixed in version 9.0.120240617.19506

Related threats