CVE-2014-2938
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0063 (0.6%)
Percentile: 70.4%
EPSS: 2026-05-06
Affects
hanon:faceid_f810_firmwarehanon:faceidhanon:faceid_f710_firmwarehanon:faceid_fk800_firmwarehanon:faceid_fa007_firmwareTechnical description
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
Published: 5/22/2014, 8:55:06 PM
Last modified: 5/6/2026, 10:30:45 PM