Vulnerabilities in Android-based PoS Terminals: A Deep Dive into PAX Technology’s Security Concerns

In the constantly evolving landscape of payment processing, Point of Sale (PoS) terminals play a crucial role. However, PAX Technology, a prominent provider of Android-based PoS terminals, faces critical vulnerabilities that can be exploited by malicious actors. In this article, we will explore the series of vulnerabilities affecting PAX terminals, their potential impact, and the necessary mitigation strategies.

Vulnerabilities in PAX PoS Terminals

The first vulnerability discovered affects PAX A920 devices, enabling attackers to downgrade the bootloader to a previous, potentially vulnerable version. This attack vector could pave the way for unauthorized access to the terminal’s functionality.

In the second vulnerability, attackers can inject kernel arguments, granting them the ability to execute arbitrary code with root privileges on any PAX PoS device. Although sandboxing prevents application interference, an attacker with root access could tamper with any application, including the payment process.

PAX A920Pro/A50 devices are vulnerable to code execution by flashing a different unsigned partition. This vulnerability poses additional risks as attackers can potentially execute malicious code, jeopardizing the integrity of the terminal’s operations.

Three critical vulnerabilities have been identified that require physical USB access. Attackers gaining physical access to a vulnerable PoS terminal could exploit these vulnerabilities, enabling various types of attacks with severe consequences.

Shell Access Vulnerabilities

Two vulnerabilities have been discovered that can be exploited by attackers with shell access. This means that unauthorized individuals can execute arbitrary commands on a vulnerable PoS device, opening the door to potential unauthorized modifications and breaches.

While these vulnerabilities raise serious concerns, it’s important to note that full exploitation requires root access or physical USB access. The presence of sandboxing mitigates the risk of application interaction. However, the potential impact remains significant, as attackers could modify transaction amounts and other related data. To address these vulnerabilities, businesses and users must prioritize security measures and implement best practices.

Upon being informed by STM Cyber and CERT Poland, PAX Technology promptly responded to the identified vulnerabilities. Recognizing the importance of responsible disclosure, they released comprehensive patches, aiming to address all the vulnerabilities. Timely patching and vigilant installation of updates are crucial in maintaining the security of PoS terminals.

Android-based PoS terminals from PAX Technology have been found to be susceptible to multiple vulnerabilities, which allow attackers to execute arbitrary code or commands. The potential risks posed by these vulnerabilities call for heightened security measures and adherence to industry best practices. Businesses and PoS terminal users must prioritize security updates, regularly patch vulnerabilities, and follow security guidelines to mitigate the risk of exploitation. By doing so, they can safeguard their operations and customers’ sensitive payment information from potential threats.

Explore more

Have Stablecoins Finally Gone Mainstream?

Introduction a Definitive Shift in Digital Payments A compelling body of evidence from a 2025 Zerohash report strongly suggests that the financial landscape has reached a pivotal moment where stablecoins are no longer confined to the niche corners of the cryptocurrency world. This research addresses the critical question of whether these digital assets have successfully transitioned into mainstream financial tools.

How Is Saudi Arabia Going Cashless So Fast?

The familiar rustle of banknotes is becoming an increasingly rare sound across Saudi Arabia as the Kingdom undergoes one of the world’s most rapid and comprehensive shifts away from physical currency. This transformation is not a gradual drift but a deliberate, accelerated pivot toward a fully digital financial landscape. The change is reshaping everything from daily coffee purchases to major

Can AI and RPA Solve the Social Housing Crisis?

The conversation surrounding social housing often centers on a simple, yet profoundly difficult, mandate to build more homes, but this focus overlooks the silent crisis unfolding within the operational heart of housing associations themselves. With tenant debt escalating and staff stretched to their breaking point, the sector is grappling with an immense internal pressure that construction alone cannot alleviate. This

Why Do B2B Buyers Crave Social Media in an AI World?

In an age where generative AI promises unparalleled efficiency and data-driven answers, a fascinating counter-trend is solidifying its place at the heart of the business-to-business purchasing process. Recent comprehensive analysis of over 17,000 global business buyers reveals that social media has ascended to become the second most meaningful source of information, surpassed only by AI-powered search tools. This finding underscores

Why B2B Marketers Should Revisit PMax by 2026

The initial skepticism that once surrounded Google’s Performance Max campaigns in the business-to-business sector is rapidly becoming a relic of a bygone advertising era. What many dismissed as a consumer-focused tool, ill-suited for the complex and lengthy B2B sales cycle, has undergone a significant transformation. Today, B2B marketers are discovering that a properly calibrated PMax campaign, fueled by high-quality data,