Back

HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word

Published Jan 15, 2024

Description

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word.

The attacker must have shell access to the device in order to exploit this vulnerability.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CERT-PL
Published Jan 15, 2024
Updated Oct 10, 2024
Reserved Sep 7, 2023

CISA Vulnrichment

Updated Aug 26, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner CERT-PL
Published Jan 15, 2024
Updated Oct 10, 2024

GitHub

No data