CVE-2023-38951
ZKTeco BioTime Arbitrary File Write and Code Execution
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
ZKTeco BioTime software, used for workforce management, contains a vulnerability that allows authenticated attackers to create or overwrite arbitrary server files via crafted requests. This could lead to the execution of malicious code with system privileges. Organizations using this software should confirm its presenc