CVE-2024-13966
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-1393
- Published
- 2025-05-27
- Last modified
- 2026-03-13
Affected products
- ZKTeco BioTime
Weakness type
Related vulnerabilities
- CVE-2026-69657 — XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the...
- CVE-2026-82698 — sambitraj Student-Management-System aca.sql default password
- CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
- CVE-2026-5269 — Navigator NCS and MCP System Accounts with Default Passwords
- CVE-2026-54445 — Vantage6: Set admin user and password from environment or configuration
- CVE-2026-35075 — Hardcoded default Password for Service Account
- CVE-2026-8672 — Default credentials for internal DB
- CVE-2026-33784 — JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access