PT-2026-82269 · Payrange · Payrange Api
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PayRange API (affected versions not specified)
Description
The PayRange API lacks proper authorization on management endpoints, allowing public access to verbose details of every device on the network, regardless of whether the requester has an account. This issue was exploited to bypass authorization and gain unrestricted access to device details across the payment network, facilitating reconnaissance of network topology and potential lateral movement to payment terminals.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Implement runtime segmentation to limit the potential blast radius of an expansion.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Payrange Api