Paxtechnology develops point-of-sale and mobile payment devices including the PayDroid, PaxStore, and A-series terminals, which are widely deployed at retail and hospitality locations. The vendor's vulnerability profile centers on authentication and command-injection weaknesses across these payment terminals, reflecting the authentication and OS-level exposure inherent to networked payment hardware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paxtechnology over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42136HIGH PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell inje | Jan 15, 2024 | 7.8 | 25 | NO | NO |
CVE-2022-26580MEDIUM PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attac | Dec 16, 2022 | 6.8 | 24 | NO | NO |
CVE-2020-36128HIGH Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access | May 7, 2021 | 8.2 | 24 | NO | NO |
CVE-2023-4818HIGH PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.
The attacke | Jan 15, 2024 | 7.6 | 23 | NO | NO |
CVE-2023-42137HIGH PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks.
The | Jan 15, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-27199MEDIUM PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypass authorization checks. | Jul 5, 2023 | 6.7 | 23 | NO | NO |
CVE-2023-27198MEDIUM PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a specific word in the command to | Jul 5, 2023 | 6.8 | 23 | NO | NO |
CVE-2022-26581MEDIUM PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in | Dec 16, 2022 | 6.8 | 23 | NO | NO |
CVE-2020-36126HIGH Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow a | May 7, 2021 | 8.1 | 23 | NO | NO |
CVE-2023-42135MEDIUM PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when f | Jan 15, 2024 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paxtechnology.
Media articles that mention a CVE ID that affects a product developed by Paxtechnology — matched by CVE ID, not by vendor name.