CVE-2023-3938: Bypassing ZkTeco-based OEM devices/ZKTeco biometric authentication system via SQLi in QR code
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM devices allows an attacker to authenticate under any user from the device database.
This issue affects
ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly others.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3938?
CVE-2023-3938 has been classified as a critical vulnerability due to its potential for unauthorized authentication.
How do I fix CVE-2023-3938?
To fix CVE-2023-3938, update the affected ZkTeco-based OEM devices to the latest firmware that addresses the SQL injection flaw.
Which devices are affected by CVE-2023-3938?
CVE-2023-3938 affects various ZkTeco-based OEM devices, including the ZkTeco ProFace X and Smartec ST-FR041ME.
What kind of attack can occur due to CVE-2023-3938?
CVE-2023-3938 allows attackers to exploit the SQL injection vulnerability to authenticate as any user in the device database.
Is it safe to use affected devices without patching CVE-2023-3938?
It is not safe to use affected devices without patching CVE-2023-3938, as they are vulnerable to unauthorized access.