CVE-2023-3939
EUVD-2023-4456521.05.2024, 10:15
Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability in ZkTeco-based OEM devices allows OS
Command Injection.
Since all the found command implementations are executed from the
superuser, their impact is the maximum possible.
This issue affects
ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec
ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0
and possibly other.Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zkteco | facedepot_7b | - ≤ 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |
| zkteco | smartec_st_fr043 | 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |
| zkteco | smartec_st_fr041me | 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |