GPU VulnDB

Database/Control plane, storage & DevOps

ZKTeco-based OEM biometric access terminals (ZKTeco ProFace X, Smartec ST-FR043/ST-FR041ME and rebadged equivalents)

CVE-2023-3939Control plane, storage & DevOpsCVE-2023-3941CVE-2023-3940CVE-2023-3943CVE-2023-3938CVE-2023-3942curated

Impact

OS command injection where every command runs as root, arbitrary file write as root via path traversal, arbitrary file read, a stack overflow with no stack canaries or PIE, and SQL injection allowing authentication as any user in the device database. This is the reader on the wall next to the door - the device that decides whether a face or a badge opens the hall. Root on it means an attacker opens the door at will, enrols their own biometric template, harvests the biometric templates and badge data of everyone who has ever entered (which is a privacy and regulatory problem on top of a security one), and keeps persistence on a device nobody ever patches. The rebadging is the trap: these terminals ship under many brand names, so an operator's asset list may say Smartec or a local integrator's label with no mention of ZKTeco anywhere. Once someone is through that door and into the cage, they reach drives holding model weights, server console ports, and the out-of-band management switch fronting every BMC in the row.

Who can reach it

Network access to the terminal for the injection and traversal paths - these devices sit on the physical-security VLAN and are frequently given a network address by whoever installed them with no ACL at all. Several of the flaws are also reachable by an attacker with brief physical proximity to the device, since the terminal is by definition mounted on the unsecured side of the door.

What to do

Firmware from ZKTeco or the OEM that rebadged the device - and this is the problem, because rebadged terminals frequently never receive the upstream fix and the OEM may no longer exist. Start by physically identifying every biometric or badge terminal in the facility and determining the actual manufacturer of the board, not the label. Where a fixed firmware exists, flash it; where it does not, replace the terminal, which is a per-door hardware cost but a small one relative to what is behind the door. Regardless: isolate reader devices onto a segment that cannot reach anything else, never allow a reader to be routable from a tenant or corporate network, and if biometric templates are stored on-device, treat them as already exposed and notify accordingly.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.