PT-2026-27106 · Shenzhen Hcc Technology · Mpos M6 Plus
Davimo
+1
·
Published
2026-03-23
·
Updated
2026-04-15
·
CVE-2026-4583
CVSS v3.1
5.0
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Shenzhen HCC Technology MPOS M6 PLUS version 1V.31-N
Description
An issue exists in the Bluetooth Handler component where the Bluetooth protocol lacks cryptographic authentication mechanisms. The system relies on a trivial single-byte XOR checksum for integrity checks, which can be recalculated by an attacker. This allows a remote attacker on the local network to perform a capture-replay manipulation to bypass authentication and inject arbitrary transaction commands without the terminal verifying the origin or authenticity of the command. This attack is considered to have high complexity and is difficult to exploit.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mpos M6 Plus