Skip to content

CVE-2014-2938

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0063 (0.6%)
Percentile: 70.4%
EPSS: 2026-05-06

Affects

hanon:faceid_f810_firmwarehanon:faceidhanon:faceid_f710_firmwarehanon:faceid_fk800_firmwarehanon:faceid_fa007_firmware

Technical description

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.

Published: 5/22/2014, 8:55:06 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam