<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — ZKTeco</title><description>Actively exploited vulnerabilities affecting ZKTeco products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/zkteco.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2023-38950 — ZKTeco BioTime Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-38950</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-38950</guid><description>ZKTeco BioTime, a workforce management and time-attendance platform, contains a path traversal flaw in its iclock API. An unauthenticated attacker — meaning no credentials are required — can craft a malicious request to read arbitrary files on the underlying system. This could expose sensitive configuration files, credentials, or other data, potentially enabling further compromise of the environment without any initial foothold.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>ZKTeco</category><category>BioTime</category></item></channel></rss>