PT-2022-17938 · Pax A930+1 · Pax A930+1
Wr3Nchsr
·
Published
2022-12-16
·
Updated
2024-10-27
·
CVE-2022-26579
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PAX A930 device with PayDroid versions 7.1.1 Virgo V04.3.26T1 20210419 through 7.1.1 Virgo V04.4.02 20211201
Description
The issue allows a root privileged attacker to install unsigned packages on the device. To exploit this, the attacker must have shell access to the device and gain root privileges. This can be done by copying the APK to
/data/app, setting the appropriate permissions, and rebooting the device.Recommendations
For PayDroid version 7.1.1 Virgo V04.3.26T1 20210419, consider restricting access to the device's shell to prevent attackers from gaining root privileges.
For PayDroid version 7.1.1 Virgo V04.4.02 20211201, avoid using the device's package installation feature until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pax A930
Paydroid