An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Biotime | Zkteco | 8.5.5 (including) | 8.5.5 (including) |
References