Executive brief
ZKTeco BioTime, a software suite used for managing employee time and attendance, contains a security flaw that exposes sensitive administrative passwords in plain text. An attacker can access these credentials remotely, potentially gaining full administrative control over the system and its data. This could lead to unauthorized access to employee records or disruption of time-tracking operations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the /base/safe_setting/ endpoint of ZKTeco BioTime. The application returns HTML containing sensitive fields, specifically 'backup_encryption_password_decrypt' and 'export_encryption_password_decrypt', in cleartext within password input fields. In versions 9.0.3 and 9.5.2, this endpoint is accessible without authentication; in version 9.0.4, it is accessible to any authenticated low-privilege user. Attackers can exploit this to retrieve administrative credentials, often matching the default admin password, leading to full system takeover. The issue is resolved in version 9.0.6.
Affected products
- ZKTeco BioTime 9.0.3, 9.0.4, 9.5.2
Timeline
- 2025-12-28: disclosed
- 2025-12-28: advisory
- 2026-06-11: patched: Vendor confirmed fix in version 9.0.6