Pax develops payment-processing terminals and point-of-sale systems including models such as ProLinOS, the A920 Pro, and PayDroid, representing embedded devices commonly deployed at merchant and transaction endpoints. The observed vulnerability surface recurs through race conditions in concurrent resource handling, improper privilege management, weak cryptographic signature verification, and insecure default permissions—weakness classes that reflect the authentication and transaction-integrity requirements of payment-terminal firmware. Current exposure levels and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pax over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28046HIGH An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting | Nov 2, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-28045HIGH An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer | Nov 2, 2020 | 7.8 | 24 | NO | NO |
CVE-2023-26980HIGH PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Andr | Apr 14, 2023 | 7.0 | 23 | NO | NO |
CVE-2020-28044MEDIUM An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, crea | Nov 2, 2020 | 6.8 | 21 | NO | NO |
CVE-2015-1193MEDIUM Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. | Jan 21, 2015 | 5.0 | 15 | NO | NO |
CVE-2015-1194MEDIUM pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive. | Jan 21, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pax.
Media articles that mention a CVE ID that affects a product developed by Pax — matched by CVE ID, not by vendor name.