What is CVE-2026-19909?
This vulnerability in PAX Technology Q80 POS terminals allows network-adjacent attackers to execute arbitrary code without authentication via 'Link Following' during 'AIP File Parsing'. It poses a critical risk of full device compromise. Affected systems urgently require the vendor's security patch.
Azərbaycanca: PAX Technology Q80 POS terminallarında aşkar edilmiş bu zəiflik şəbəkə üzərindən autentifikasiya tələb etmədən ixtiyari kod icrasına imkan verir. 'AIP File Parsing' zamanı 'Link Following' qüsuru cihazın tam ələ keçirilməsinə səbəb ola bilər. Təsirə məruz qalan cihazlarda istehsalçının təqdim edəcəyi təhlükəsizlik yeniləməsinin təcili tətbiqi vacibdir.
FAQ2
Does the CVE-2026-19909 vulnerability in PAX Technology Q80 POS terminals require authentication?
No, this vulnerability allows arbitrary code execution over the network without authentication.
During which operation is the CVE-2026-19909 vulnerability exploited on PAX Technology Q80 devices?
The vulnerability is exploited via a 'Link Following' flaw during 'AIP File Parsing'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.