PT-2022-17938 · Pax A930+1 · Pax A930+1

Wr3Nchsr

·

Published

2022-12-16

·

Updated

2024-10-27

·

CVE-2022-26579

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PAX A930 device with PayDroid versions 7.1.1 Virgo V04.3.26T1 20210419 through 7.1.1 Virgo V04.4.02 20211201
Description The issue allows a root privileged attacker to install unsigned packages on the device. To exploit this, the attacker must have shell access to the device and gain root privileges. This can be done by copying the APK to /data/app, setting the appropriate permissions, and rebooting the device.
Recommendations For PayDroid version 7.1.1 Virgo V04.3.26T1 20210419, consider restricting access to the device's shell to prevent attackers from gaining root privileges. For PayDroid version 7.1.1 Virgo V04.4.02 20211201, avoid using the device's package installation feature until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2022-26579

Affected Products

Pax A930
Paydroid