Sale of a 0-day exploit for Castles VEGA3000 POS terminals
Dark Web2026-07-13, 10:42
For informational purposes only.
Vulnerability type: Physical Access Secrets Extraction (extraction of secrets through physical access without opening the device casing)
The seller is offering an exploit for a vulnerability that allows an attacker with physical access to a VEGA3000 terminal to extract secrets stored on the device without opening the casing. The practical risk of this vulnerability is the possibility of extracting secrets (potentially encryption keys for PIN blocks, TLS certificates for the terminal, DUKPT master keys) if a cashier, service technician, or attacker with temporary access to the device gains physical access to it at the point of sale.
VEGA3000 is a line of PIN-pad terminals from the Taiwanese company Castles Technology, running on Linux with an open architecture, certified according to PCI PTS 4.x, and supporting EMV contact/contactless. These devices are widely used in both mobile (Bluetooth/Wi-Fi/4G) and stationary configurations, and are used by merchants and integrated with payment platforms such as USAePay and Trust Payments.
Castles Technology is a Taiwanese manufacturer founded in 1993, and is one of the global leaders in the POS terminal market. According to industry reports, the top 5 global manufacturers hold over 65% of the market, and Castles Technology consistently ranks among them, alongside Ingenico, Verifone, PAX Technology, and Newland. The company claims to have tens of millions of terminals deployed worldwide and partners with banks, acquirers, ISVs, and PSP providers in the retail, hospitality, gas station, and transportation sectors.
Vendors
More
Products