Executive brief
A vulnerability in Suprema BioStar 2, a security platform used for access control and biometric identification, allows an attacker to crash the server remotely. By sending a specific request to the system, an attacker can disable the server and stop all connected door readers from functioning. This results in a total service outage that requires a manual restart to restore building security operations.
Technical details
The vulnerability is classified as an Uncaught Exception (CWE-248) within the '/api/migration' endpoint of the Suprema BioStar 2 Server. An unauthenticated remote attacker can trigger this exception by sending a specially crafted HTTP POST request. Because the application fails to handle the resulting error, critical server processes halt, leading to a complete Denial of Service (DoS). Exploitation requires no user interaction or privileges and results in the failure of access control readers and third-party integrations until a manual service restart is performed. The vendor has released patches to address this issue.
Affected products
- Suprema BioStar 2 (Server) 2.9.8, 2.9.10, 2.9.11
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched