PAX A920Pro/A50 devices with PayDroid_8.1...
Moderate severity
Unreviewed
Published
Jan 15, 2024
to the GitHub Advisory Database
•
Updated Oct 10, 2024
Description
Published by the National Vulnerability Database
Jan 15, 2024
Published to the GitHub Advisory Database
Jan 15, 2024
Last updated
Oct 10, 2024
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition.
The attacker must have physical USB access to the device in order to exploit this vulnerability.
References