Version 1.0.3 (Build No. 1.0.3.171)
Release|2026-09-22
New Features and Improvements
- Supported new device
- XPass Q2: XPQ2-DPB
- XPass 2 (V2): XP2-GDPB-V2, XP2-GKDPB-V2, XP2-MAPB-V2, XP2-MDPB-V2, XP2-MAPB-H-V2
- Added real-time status monitoring and direct control of doors and elevators in the Monitoring preview
- Added face authentication features
- Added support for Multi Face Authentication (device license required)
- Added support for tailgating prevention (Anti-Tailgating)
- Added support for Duplicate Authentication Prevention
- Added Include On-Site Users Only mode to Roll Call
- Added Scan ID feature to automatically fill in user information using an ID
- Added Export/Import Device Configuration feature
- Supported EV2 Secure Messaging authentication for DESFire EV2 and EV3 cards.
- Added the ability to select and batch control multiple devices in Monitoring
- Run Unlock Device, Release Lockout, Stop Action, Reconnect, and Reboot on multiple devices at once
- Added support for Select All and group selection in the Monitoring event filter
- Added the ability to select and batch control multiple doors, elevators, and advanced access control in Monitoring
- Added a feature to manage users with long-term inactivity
- View users with long-term inactivity based on Last Access
- Set a policy to automatically deactivate users based on conditions
- Send a pre-notification email to designated recipients before auto deactivation
- Separated firmware builds for CE and Global (Non-CE) products.
CE and Global (Non-CE) products can be identified via the label sticker on the back of the product. The Master Admin feature is enabled only on products with a label bearing the CE mark.
- Added Auth Fail Lockout feature, which locks the device after repeated PIN authentication failures.
- Expanded allowed characters for User ID and User Name
- Added support for periods (.) in User ID
- Added support for periods (.) and apostrophes (') in User Name
- Added the Audit Trail feature to T&A
- Added a filter to the Monitoring status tree that shows only items requiring attention
- Added the ability to configure account permissions at the submenu level
- Added the Idle Screen Video Playback feature
- Supported models: BioStation 3 Max
- Supported an option to select QR authentication using the device camera upon Camera QR license activation on XS2-QDPB and XS2-QAPB models.
- Added the ability to display frequently used Quick Actions directly in the header
- Added the Door Control through Authentication feature, which unlocks or normalizes a door through user authentication
- Added the ability to display and unlock locked devices in the Monitoring status tree
- Improved license policy and added bulk activation
- Feature add-on licenses can now be activated on the Essential tier
- Separated Advanced Access Control into individual licenses
- Added the ability to activate multiple license keys at once
- Added the report save feature to All Events and Alert History in the Data menu
- Improved the Access Control Audit Trail feature
- Expanded logging to capture previously missing actions
- Recorded before-and-after values when settings or information change
- Added logging of user information access
- Improved the Device menu tree to remember the expanded/collapsed state per account
- Added element-specific icons and improved the expand/collapse method in the Monitoring status tree
- Improved Monitoring to display the event log across the full screen when there are no maps or cameras to show
- Improved the Settings menu with a group tree structure
- Improved the VMS certificate installation process
- Improved the T&A screen UI design
- Improved the Monitoring map status tree to move to the corresponding map when double-clicking a facility
- Improved the device hardware version to display the same value as the product label (requires supported firmware)
- Changed Secure Communication with Device to be enabled by default
- Improved group mapping for users belonging to multiple groups in Entra ID.
- Improved Send Face Mobile Enrollment Link to indicate in the Audit Trail that the change was made via this feature.
- Improved the display timing and behavior of the notification popup for an existing BioStar X folder when upgrading from BioStar 2 to BioStar X.
- Improved the behavior where unnecessary error popups appeared due to response delays during Sync Device.
- Improved the group selection UI when creating custom levels.
- Security vulnerability improvements
- Upgraded internal server and client communication channels to TLS 1.3
- Updated AngularJS and jQuery versions
- Improved Reverse Tabnabbing vulnerability
- Enhanced session cookie security
- Updated the Log4j library version
- Updated Java Runtime Environment (JRE) version
- Improved SQL Injection vulnerability
- Improved a redirect URL security vulnerability during Entra ID login
- Updated the commons-text library version
- Updated the OpenSSL library version
- Updated security vulnerability-related libraries
- Improved security vulnerabilities in Entra ID integrated login authentication.
- Improved login to transmit passwords in encrypted form.
- Enhanced security by requiring the current password when changing your own password.
- Time & Attendance security vulnerability improvements
- Improved an SSL certificate-related security vulnerability
- Updated Node.js and library versions
- Improved Face user synchronization performance.
- Improved Custom Report query performance when retrieving data over a wide date range.
- Performance and query improvements in large-scale environments
- Improved face authentication performance in environments with many users and face data
- Improved bulk edit speed for 1,000 or more users
- Fixed query failures when Device, Access Level, or Credential numbers are large
- Improved event query performance for custom accounts using specific device groups.
- Improved Door Status query performance in Multi Communication Server environments.
- Improved the query performance of the Status tab in the Access Group screen in large-scale environments.
- Improved the long synchronization time when saving Door settings.
- Improved slow server startup in environments with many registered licenses.
- Improved slow user retrieval in environments with many Access Groups.
- Improved slow loading of the Elevator detail screen in environments with many devices.
- Improved synchronization in Multi Communication Server environments
- Improved so that each server processes only its own devices for firmware synchronization
- Improved User Group query performance in environments with many users
- Improved delays in saving settings when the Dashboard has many components.
- Improved operator permission check performance and Zone permission handling
- Improved operator permission check performance in environments with many targets
- Improved Zone permissions being applied incorrectly in some cases
- Improved device list tree loading speed in environments with many devices.
- Improved device synchronization speed in environments with many devices.
- Improved device synchronization by sending updates only for modified users when Access Group members are changed.
- Improved overall device synchronization performance and resolved device disconnection issues by sending only device-relevant information during sync.
- Added removal of unused files during upgrade.
Bug Fixes
- During video playback, the seekbar timeline and the time information at the knob position do not match. Affects version: 1.0.0
- Viewing the preview of a disconnected Slave device does not display the device group. Affects version: 1.0.0
- Exporting to CSV after selecting all users exports them in user creation order instead of User ID order. Affects version: 1.0.0
- Switching views or exiting full screen while a video is paused causes the video to switch to playing. Affects version: 1.0.0
- When sorting (Order By) columns in the User List in an encrypted environment with User IDs that differ only by case, the sort order is applied incorrectly. Affects version: 1.0.0
- When printing the User List after selecting all columns including Custom User Fields, Credential-related columns appear blank. Affects version: 1.0.0
- Viewing the preview of real-time event logs containing user information that does not exist on the server displays an empty User field. Affects version: 1.0.0
- When importing a CSV file with Mobile Access Card information, the card is issued only in the Airfob Portal even if user creation fails. Affects version: 1.0.0
- When importing a CSV file with Mobile Access Card information, a card is issued in the Airfob Portal and an error occurs if User ID is not selected on the column mapping screen. Affects version: 1.0.0
- Importing a CSV file without Mobile Access Card information deletes the card from BioStar 2 while retaining it in the Airfob Portal. Affects version: 1.0.0
- The enlarge image button label in the Monitoring event preview area was displayed in English even when the language was set to Korean. Affects version: 1.0.0
- Unrelated settings were disabled or an info icon was incorrectly displayed when setting Suprema Smart Card Layout or Custom Smart Card Layout to None in Device Detail page. Affects version: 1.0.0
- Loading not completing when an administrator without device permissions accesses the Occupancy Limit zone Preview in Monitoring. Affects version: 1.0.0
- Column not printed when a Custom User Field is added and included in the Column Layout before printing. Affects version: 1.0.0
- Options in CSV Import hidden and unable to proceed when the browser zoom level is increased. Affects version: 1.0.0
- Error popup occurring when reissuing a Mobile Access Card after deleting it on the user detail page. Affects version: 1.0.0
- Incorrect screen displayed after completing registration in environments with many users in T&A. Affects version: 1.0.0
- Error popup occurring intermittently when accessing the device detail page. Affects version: 1.0.0
- Synchronization errors occurring on multiple devices when deleting a device after deleting a door in a Multi Communication Server environment. Affects version: 1.0.0
- Checkboxes not working correctly when selecting/deselecting master sub-devices in Set Filters of the Dashboard. Affects version: 1.0.2
- Image files saved without detailed information in the filename when downloading images in Custom Report. Affects version: 1.0.2
- Lines misaligned when a User Group name is long in the tree of the Users Information screen. Affects version: 1.0.2
- Dump files generated after PC boot in an MSSQL environment. Affects version: 1.0.0
- No action or error message occurring when viewing the Image Log of a disconnected device in All Events. Affects version: 1.0.2
- Errors occurring when importing a device's Event Log that exceeds the maximum storage capacity. Affects version: 1.0.0
- Inactive users incorrectly shown as active when searching users via the API. Affects version: 1.0.0
- Logs from certain devices not appearing in the Event Log and Real-time Log in an MSSQL environment. Affects version: 1.0.0
- App crashing when fingerprint scanning fails with BioMini Slim2 in USB Agent. Affects version: 1.0.0
- Wiegand Card IDs not displayed correctly when generating card-related reports in Report. Affects version: 1.0.0
- Time Zone fixed to UTC+9 instead of the local server time on the first installation of BioStar X. Affects version: 1.0.0
- Titles not displayed on some screens when using a monitor in portrait mode. Affects version: 1.0.0
- Null displayed in the name field when a user without a name is selected as a search condition and the screen is refreshed in T&A Report. Affects version: 1.0.0
- Errors occurring when accessing the Settings menu after upgrading BioStar 2 installed in a Korean-named folder path to BioStar X. Affects version: 1.0.0
- Errors occurring and the service shutting down when applying settings to certain devices. Affects version: 1.0.1
- Schedules failing to be created and the loading state persisting in T&A. Affects version: 1.0.0
- Backup failing when using a custom port in an MSSQL (Windows Authentication) environment. Affects version: 1.0.0
- Plugin icons not appearing in the Launcher after backup and restore. Affects version: 1.0.0
- Some files remaining undeleted after uninstalling the T&A package. Affects version: 1.0.0
- Users not synchronizing correctly to Time & Attendance when adding a large number of users and User Groups via CSV Import in a Windows Authentication environment. Affects version: 1.0.0
- Duplicate leave entries created when registering Leave for multiple users in T&A. Affects version: 1.0.0
- Time adjustment buttons not being disabled when adding a non-worked leave in a T&A Schedule. Affects version: 1.0.0
- Errors occurring when disabling Optimized Punchlog in T&A in MSSQL environments. Affects version: 1.0.0
- Unnecessary characters displayed in the popup message when creating a schedule in T&A. Affects version: 1.0.0
- Error logged when creating a holiday in T&A menu with the same name as a holiday created in Schedule setting menu. Affects version: 1.0.0
- Some attendance records missing when using multiple devices in T&A in an MSSQL environment. Affects version: 1.0.0
- Holidays not applied to schedules and processed as absences when there are more than 100 holidays in T&A. Affects version: 1.0.0
- Memory usage increasing abnormally when using T&A for extended periods. Affects version: 1.0.0
- Warning popup appearing when the refresh button is clicked repeatedly in the Time & Attendance calendar view. Affects version: 1.0.0
- Some communication servers failing to connect after a reboot. Affects version: 1.0.0
- Mobile cards incorrectly added to the Deleted CSN Mobile Card list when deleting them via CSV import in a Dynamic site environment. Affects version: 1.0.0
- Browser freezing when importing a large number of user groups from Active Directory/Entra ID. Affects version: 1.0.0
- Some event names not displayed correctly after upgrade. Affects version: 1.0.0
- Incorrect data displayed in Custom Report when changing rows per page after navigating pages. Affects version: 1.0.2
- Intermittent errors occurring during restore in an MSSQL (Windows Authentication) environment. Affects version: 1.0.2
- Active Directory/Entra ID integration failing in language environments with different numeral representations, such as Arabic. Affects version: 1.0.0
- Users who have exited still shown as inside in the Muster Report. Affects version: 1.0.0
- Time and Attendance synchronization not proceeding after an error occurs during synchronization. Affects version: 1.0.0
- Remote Access failing to start or save properly. Affects version: 1.0.2
- Old IP information remained and caused improper operation when restoring with a changed server IP Affects version: 1.0.2
- Synchronization failing when an Entra ID group name contains special characters such as commas (,) or equal signs (=). Affects version: 1.0.0
- Errors occurring due to invalid dates when modifying access groups via the API. Affects version: 1.0.0
- User ID not displayed in Face synchronization failure events. Affects version: 1.0.0
- The same firmware appeared twice when upgrading firmware with both XPass 2 (V2) and XPass 2 Keypad (V2) selected in the Device list Affects version: 1.0.0
- The Apply button did not work when saving RS485 settings on the device detail screen Affects version: 1.0.0
- The server did not restart automatically after an abnormal shutdown Affects version: 1.0.0
- Features supported by the new firmware were not displayed on the screen after a firmware upgrade Affects version: 1.0.1
- The report title was not displayed when printing or exporting to PDF if the Roll Call report title was in Thai Affects version: 1.0.0
- The server shut down abnormally and interrupted service for all users when a logged-in user was deleted Affects version: 1.0.0
- The event was not displayed in the event log when controlling a door in Monitoring without ever opening the preview Affects version: 1.0.0
- No system backup file was created in Time & Attendance environments upgraded from BioStar 2 Affects version: 1.0.0
- Deleting all Output Signals in the Alert settings failed to process Affects version: 1.0.0
- Anti-Passback list retrieval was delayed when entering the Advanced Access Control screen after creating a Muster zone, making the menu inaccessible Affects version: 1.0.0
- Bookmarks and notifications were not recorded in the VMS when the web port was set to a non-default port during installation Affects version: 1.0.0
- After a user group operation failed once, subsequent user changes were not applied to devices until the server was restarted Affects version: 1.0.0
- Images could not be added when setting the BioStation 3 Max home screen logo to a slide show Affects version: 1.0.2
- Users belonging to both Access Group disappeared from devices after reconnection when the Access Level of the two groups were swapped while the devices were disconnected Affects version: 1.0.0
- Events from a deleted device remained and delayed event logging for other devices, and the server log grew rapidly if the deleted device stayed connected Affects version: 1.0.2
- Real-time event, alarm, and task completion notifications were not displayed on the screen when their delivery failed Affects version: 1.0.0
- IP information was not displayed in the User column when viewing login failure lockout events in Custom Report Affects version: 1.0.0
- The scroll bar in the User tree and the Settings screen could not be moved with the mouse Affects version: 1.0.0
- Some users were not delivered to devices during full device synchronization, yet the synchronization was marked as complete, and they were still not delivered even after resynchronizing Affects version: 1.0.0
- Changing the personal data encryption settings logged the user out Affects version: 1.0.0
- The authenticated user name was not displayed in the Occupancy Limit alert Affects version: 1.0.0
- On the Custom Report screen, the User Name column also displayed the user ID, duplicating the User ID column Affects version: 1.0.0
- User synchronization on BioStation 3 Max was slow in specific device synchronization mode environments Affects version: 1.0.2
- Re-entering the Door Status tab after applying a manual Lock/Unlock (Timed, Permanent) to a door relay does not display the status change tooltip when clicking the Door Relay icon. Affects version: 1.0.0
- Re-entering the Door Status tab after applying a manual Lock/Unlock (Permanent) to a floor relay does not display the status change tooltip when clicking the Floor Relay icon. Affects version: 1.0.0