CVE-2023-3939: Multiple command injection in ZkTeco-based OEM devices
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the found command implementations are executed from the superuser, their impact is the maximum possible. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly other.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3939?
CVE-2023-3939 is considered critical due to its potential for OS command injection with superuser privileges.
How do I fix CVE-2023-3939?
To fix CVE-2023-3939, ensure that your ZkTeco devices are updated to the latest firmware version which addresses this vulnerability.
Which products are affected by CVE-2023-3939?
CVE-2023-3939 affects ZkTeco ProFace X, ZkTeco ST-FR043, and ZkTeco ST-FR041ME devices.
What is an OS command injection vulnerability like CVE-2023-3939?
An OS command injection vulnerability, such as CVE-2023-3939, allows an attacker to execute arbitrary commands on the host operating system.
Can CVE-2023-3939 lead to data loss?
Yes, CVE-2023-3939 can lead to data loss or system compromise as it provides attackers with elevated command execution capabilities.