CVE-2023-38030

Publication date

2023-08-28 06:44:16

Family

twcert

State

PUBLISHED

Description

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.