Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-19910
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability
CVE-2026-19908
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability
CVE-2026-19909
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
CVE-2023-42133
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.
CVE-2023-42137
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.
