CVE-2023-3654: Cashit Cashit!

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

Affected products

  • Cashit Cashit!: up to and including 03.a06rks_2023.02.37

Published 2023-10-03. Last modified 2026-06-17.