Vulnerabilities in Android-based PoS Terminals: A Deep Dive into PAX Technology’s Security Concerns

In the constantly evolving landscape of payment processing, Point of Sale (PoS) terminals play a crucial role. However, PAX Technology, a prominent provider of Android-based PoS terminals, faces critical vulnerabilities that can be exploited by malicious actors. In this article, we will explore the series of vulnerabilities affecting PAX terminals, their potential impact, and the necessary mitigation strategies.

Vulnerabilities in PAX PoS Terminals

The first vulnerability discovered affects PAX A920 devices, enabling attackers to downgrade the bootloader to a previous, potentially vulnerable version. This attack vector could pave the way for unauthorized access to the terminal’s functionality.

In the second vulnerability, attackers can inject kernel arguments, granting them the ability to execute arbitrary code with root privileges on any PAX PoS device. Although sandboxing prevents application interference, an attacker with root access could tamper with any application, including the payment process.

PAX A920Pro/A50 devices are vulnerable to code execution by flashing a different unsigned partition. This vulnerability poses additional risks as attackers can potentially execute malicious code, jeopardizing the integrity of the terminal’s operations.

Three critical vulnerabilities have been identified that require physical USB access. Attackers gaining physical access to a vulnerable PoS terminal could exploit these vulnerabilities, enabling various types of attacks with severe consequences.

Shell Access Vulnerabilities

Two vulnerabilities have been discovered that can be exploited by attackers with shell access. This means that unauthorized individuals can execute arbitrary commands on a vulnerable PoS device, opening the door to potential unauthorized modifications and breaches.

While these vulnerabilities raise serious concerns, it’s important to note that full exploitation requires root access or physical USB access. The presence of sandboxing mitigates the risk of application interaction. However, the potential impact remains significant, as attackers could modify transaction amounts and other related data. To address these vulnerabilities, businesses and users must prioritize security measures and implement best practices.

Upon being informed by STM Cyber and CERT Poland, PAX Technology promptly responded to the identified vulnerabilities. Recognizing the importance of responsible disclosure, they released comprehensive patches, aiming to address all the vulnerabilities. Timely patching and vigilant installation of updates are crucial in maintaining the security of PoS terminals.

Android-based PoS terminals from PAX Technology have been found to be susceptible to multiple vulnerabilities, which allow attackers to execute arbitrary code or commands. The potential risks posed by these vulnerabilities call for heightened security measures and adherence to industry best practices. Businesses and PoS terminal users must prioritize security updates, regularly patch vulnerabilities, and follow security guidelines to mitigate the risk of exploitation. By doing so, they can safeguard their operations and customers’ sensitive payment information from potential threats.

Explore more

Ethereum Plans Major Glamsterdam Upgrade for Late 2026

Ethereum developers are currently finalizing the specifications for the Glamsterdam hard fork, which represents the next major milestone in the network’s ongoing evolution toward a more scalable and efficient global computer. This upcoming transition is not merely a routine update but a comprehensive overhaul of several critical components that have defined the network since its inception. By addressing long-standing technical

How Does Databricks CustomerLake Redefine the Agentic CDP?

The landscape of customer data management is currently undergoing a seismic transformation as the traditional boundaries between storage, analysis, and execution are being dismantled by the rise of the Data Intelligence Platform. For years, enterprises have struggled with the fragmentation tax, which represents the hidden cost of moving, cleaning, and syncing customer information across dozens of disconnected marketing clouds and

KDE Releases Plasma 6.7 with Per-Screen Virtual Desktops

The sheer complexity of contemporary digital workspaces often leads to a phenomenon where users feel overwhelmed by the literal lack of physical and virtual boundaries across their hardware. For years, the traditional approach to virtual desktops treated all connected displays as a singular, unified canvas, meaning that switching a workspace on one screen would force a transition on all others

Is the Fixed-Price AI Subscription Model Sustainable?

The rapid expansion of generative artificial intelligence has fundamentally transformed the digital landscape, yet the industry remains tethered to a subscription-based pricing model that may soon prove mathematically impossible to sustain. While the initial wave of adoption was fueled by the accessibility of flat-rate subscriptions, the underlying economics of massive compute clusters suggest a growing disconnect between user fees and

Will Agentic Automation Drive EMEA’s Autonomous Enterprise?

The transition from experimental artificial intelligence to deep-seated industrial application has reached a critical inflection point where simple task execution no longer suffices for the modern enterprise. As organizations across the Europe, Middle East, and Africa region navigate the complexities of a digital-first economy, the focus is pivoting toward Agentic Process Automation to bridge the gap between human intuition and