An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Biotime |
Zkteco |
8.5.5 (including) |
8.5.5 (including) |
References