CVE-2023-42133: Pax Pos Terminals

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

Affected products

  • Pax Pos Terminals: before 11.1.61_20240226 (fixed in 11.1.61_20240226)
  • Paxtechnology Paydroid: before 11.1.61_20240226 (fixed in 11.1.61_20240226)

Published 2024-10-11. Last modified 2026-06-17.