Skip to content

PAX Technology vulnerabilities

3 CVEs tracked

PAX Technology appears in our reporting in the context of its payment terminals. The main theme involves critical vulnerabilities, specifically on the Q80 model, allowing remote code execution without authentication. Reports indicate network-adjacent attackers could gain full control of the affected device. Defenders should focus on network-level isolation for Q80 models, specifically regarding CVE-2026-19908 (missing authentication in XCB Daemon), CVE-2026-19909 (Link Following in AIP file parsing), and CVE-2026-19910 (application installer signature verification bypass).

Azərbaycanca: PAX Technology ödəniş terminalları kontekstində hesabatlarımızda görünür. Əsas diqqət cəlb edən məsələ, cihazda autentifikasiya olmadan uzaqdan kod icrasına imkan verən kritik zəifliklərdir. Hesabatlar, şəbəkədə yaxın olan təcavüzkarların qurban cihazda tam nəzarəti ələ keçirə biləcəyini göstərir. Müdafiəçilər xüsusilə CVE-2026-19908 (autentifikasiya yoxluğu), CVE-2026-19909 (AIP faylı emalında `Link Following` hücumu) və CVE-2026-19910 (tətbiq imza yoxlamasından yan keçmə) ilə bağlı Q80 modellərini şəbəkə səviyyəsində izolyasiya etməyə fokuslanmalıdır.

This vendor's CVEs3

This hub is built from skopnix's own reporting on PAX Technology: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.