TGViewer
Android Security & Malware Android Security & Malware @androidmalware · 44.7K subscribers
Post #2133 8.46K
Android-based PAX Technology Point of Sale (POS) vulnerabilities
CVE-2023-42133 - Reserved
CVE-2023-42134 - Signed partition overwrite and subsequently local code execution as root via hidden bootloader command
CVE-2023-42135 - Local code execution as root via kernel parameter injection in fastboot
CVE-2023-42136 - Privilege escalation from any user/application to system user via shell injection binder-exposed service
CVE-2023-42137 - Privilege escalation from system/shell user to root via insecure operations in systool_server daemon
CVE-2023-4818 - Bootloader downgrade via improper tokenization
https://blog.stmcyber.com/pax-pos-cves-2023/
STM Cyber Blog Android-based PAX POS vulnerabilities (Part 1) - STM Cyber Blog In this article, we present details of 6 vulnerabilities on the Android POS devices made by the worldwide known company PAX Technology.
  • 👍 13
  • ❤ 1
More from @androidmalware
  1. Oct 7, 2026CVE-2026-23866: Finding a Whatsapp NDay https://numb3rs.re/posts/cve-2026-23866-finding-a-…
  2. Oct 1, 2026CVE-2026-86950: The Great Glyph Grift An in-the-wild iOS bug with a possible WhatsApp zero…
  3. Sep 29, 2026CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability…
  4. Sep 29, 2026How we found 24 Android vulnerabilities using our open source AI security agent https://gi…
  5. Sep 29, 2026From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat https://www.cl…
  6. Sep 28, 2026apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, s…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →