CVE-2026-97866: Zhonglun CloudPOS Automatic Update Program.cs channel accessible
A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic Update. Executing a manipulation of the argument version/url/packagekey/package name can lead to channel accessible by non-endpoint. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What systems are in scope?
The issue is reported in Zhonglun CloudPOS 3.0 and involves the Automatic Update component's Program.cs functionality. No affected or fixed build range beyond version 3.0 is provided.
What does an attacker need to exploit this issue?
The attack can be launched remotely without stated privileges or user interaction. Exploitation requires manipulating the version, url, packagekey, or package name arguments, and is described as highly complex and difficult.
Are publicly available exploits a concern?
Yes. Public exploit availability is reported, so organizations using the affected product should treat attempted exploitation as plausible despite the stated complexity.
What can be done if no vendor fix is available?
The available information does not identify a vendor response or a patch. As an interim measure, restrict remote access to the Automatic Update functionality and limit who or what can supply its version, URL, package key, and package-name arguments.