logo

PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions

ID: a9c431b9-6dc6-5a1a-ab3a-19f8db44137d

STIX ID: report--a9c431b9-6dc6-5a1a-ab3a-19f8db44137d

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-01-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

STM Cyber R&D reverse-engineered Android-based PAX PoS terminals and reported several high-severity vulnerabilities (CVE-2023-42133 [details withheld], CVE-2023-42134, CVE-2023-42135, CVE-2023-42136, CVE-2023-42137, CVE-2023-4818) that enable local code execution, privilege escalation to root, and bootloader downgrade; successful exploitation could let attackers tamper with payment transactions and amounts. Some issues require physical USB access or prior shell access; vulnerabilities were responsibly disclosed and PAX released patches in November 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.