← Vulnerability feed

Vulnerability record · CVE-2023-38950 · published 3 August 2023

CVE-2023-38950: ZKTeco BioTime iclock API path traversal allows unauthenticated file read

ZZkteco · Biotime

The iclock API in ZKTeco BioTime v8.5.5 is vulnerable to path traversal (CWE-22), letting an unauthenticated attacker read arbitrary files by supplying a crafted payload. The flaw was fixed in ZKBioTime version 9.0.120240617.19506. Because the endpoint is reachable over the network without credentials, it exposes sensitive files on internet-facing or internal deployments.

7.5 CVSS 3.1 High CISA KEV since 19 May 2025 EPSS 92% · top 0.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
9 Jul 2026Last modified by NVD

Description

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a public exploit, unauthenticated network reachability, and a very high EPSS score, making active exploitation likely.

What it is

The iclock API in ZKTeco BioTime v8.5.5 is vulnerable to path traversal (CWE-22), letting an unauthenticated attacker read arbitrary files by supplying a crafted payload. The flaw was fixed in ZKBioTime version 9.0.120240617.19506. Because the endpoint is reachable over the network without credentials, it exposes sensitive files on internet-facing or internal deployments.

Impact

An attacker can read arbitrary files from the server, which may include configuration data, credentials, or other sensitive material. There is no integrity or availability impact per the CVSS vector; the gain is information disclosure.

Attack surface

Reached over the network via the iclock API (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication and no user interaction are required. Any host exposing the BioTime iclock endpoint is a candidate target.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-05-19, and a public exploit reference (Packet Storm) exists; EPSS is 0.84702 (99.7th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade ZKTeco BioTime to version 9.0.120240617.19506 or later, which contains the fix.
  • If immediate patching is not possible, restrict network access to the iclock API to trusted hosts only and remove it from internet exposure.
  • Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
  • Monitor for and block path traversal patterns (e.g., ../ sequences) targeting the iclock endpoint at the web server or WAF layer.
  • Rotate any credentials or secrets that may have been stored in files readable through the vulnerable endpoint.

Detection

  • Search web/proxy logs for requests to the iclock API containing traversal sequences such as ../, ..%2f, or encoded variants.
  • Alert on unusual file-read activity or access to sensitive paths (configuration, credential, or system files) originating from the BioTime service account.
  • Monitor for scanning or exploitation attempts against BioTime iclock endpoints from external or untrusted source IPs.
  • Review outbound or lateral connections from BioTime hosts that could indicate data exfiltration following file reads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-38950 to the Known Exploited Vulnerabilities catalog on 19 May 2025 as "ZKTeco BioTime Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38950 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38951Zkteco biotime path traversal vulnerabilityZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi…EPSS 3.3%7.5CVE-2023-51142Zkteco biotime information exposure vulnerabilityAn issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.EPSS 0.73%7.5CVE-2023-38952Zkteco biotime vulnerabilityInsecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids …EPSS 2.7%7.5CVE-2023-38949Zkteco biotime vulnerabilityAn issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web …EPSS 0.42%6.9CVE-2024-13966Zkteco biotime vulnerabilityZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '12345…EPSS 0.39%6.8CVE-2022-38803Zkteco biotime cross-site scripting vulnerabilityZkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can re…EPSS 0.63%6.5CVE-2023-51141Zkteco biotime insecure direct object reference vulnerabilityAn issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone…EPSS 0.66%6.2CVE-2022-38802Zkteco biotime cross-site scripting vulnerabilityZkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift,…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2023-38950), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.