CVE-2022-26580: OS Command Injection
PAX A930 device with PayDroid7.1.1VirgoV04.3.26T120210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26580?
CVE-2022-26580 is considered a critical vulnerability due to the potential for command injection through physical USB access.
How do I fix CVE-2022-26580?
To address CVE-2022-26580, ensure that the affected PAX A930 device is updated to a patched version that mitigates the command injection vulnerability.
What devices are affected by CVE-2022-26580?
CVE-2022-26580 affects the PAX A930 device running PayDroid version 7.1.1_Virgo_V04.3.26T1_20210419.
What could an attacker achieve by exploiting CVE-2022-26580?
An attacker exploiting CVE-2022-26580 can execute arbitrary commands on the device through the ADB daemon shell service.
Is physical access required to exploit CVE-2022-26580?
Yes, exploiting CVE-2022-26580 requires physical USB access to the vulnerable PAX A930 device.