Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pax

First CVE: Jan 21, 2015Active for: 12 yearsTotal CVEs: 6

Pax develops payment-processing terminals and point-of-sale systems including models such as ProLinOS, the A920 Pro, and PayDroid, representing embedded devices commonly deployed at merchant and transaction endpoints. The observed vulnerability surface recurs through race conditions in concurrent resource handling, improper privilege management, weak cryptographic signature verification, and insecure default permissions—weakness classes that reflect the authentication and transaction-integrity requirements of payment-terminal firmware. Current exposure levels and exploitation activity are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 79% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pax over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2015
11 years ago
Most Recent CVE
Apr 14, 2023
1,197 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-28046HIGH
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting
Nov 2, 20207.824NONO
CVE-2020-28045HIGH
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer
Nov 2, 20207.824NONO
CVE-2023-26980HIGH
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Andr
Apr 14, 20237.023NONO
CVE-2020-28044MEDIUM
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, crea
Nov 2, 20206.821NONO
CVE-2015-1193MEDIUM
Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
Jan 21, 20155.015NONO
CVE-2015-1194MEDIUM
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
Jan 21, 20154.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (50.0%)
Network0 (0.0%)
Unknown2 (33.3%)
Physical1 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High1 (16.7%)
Unknown2 (33.3%)
User Interaction
None4 (66.7%)
Unknown2 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None1 (16.7%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pax.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pax — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pax's Products

View all 1 CNAs →

Top CWEs