Suprema BioStar 2 Insecure Password Change Vulnerability

Vulnerability

A vulnerability in Suprema's BioStar 2 access control management system, specifically in version 2.9.11.6, allows users to change their password without entering the current one. This client-side flaw can be exploited, particularly in conjunction with other vulnerabilities, to gain unauthorized access to user accounts and potentially compromise the system.

Impact

Exploitation of this vulnerability could lead to unauthorized account access, allowing an attacker to take over a user's account permanently.

Reproduction

To reproduce this vulnerability, send a request to the BioStar 2 API users endpoint, including a new password in the request body but omitting the current password. The server will accept the request and change the password successfully. After the password is changed, it can be used to log in to the account, indicating that the password change was successful.

Remediation

Contact Suprema for the patch available in version 2.9.11.

Added: Mar 4, 2026, 11:21 PM
Updated: Mar 4, 2026, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.3
exploitability
6.2
remediation
0.0
relevance
3.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.