CVE-2025-61234
7.5Dataphone · A920
An unauthenticated access control vulnerability in Dataphone A920 v2025.07.161103 exposes a local network service on port 8888, allowing unauthorized interaction and system information disclosure.
Executive summary
An unauthenticated access control flaw in the Dataphone A920 device allows remote attackers to interact with internal services and disclose sensitive system information, presenting a significant security risk.
Vulnerability
This vulnerability involves incorrect access control that exposes a service on port 8888 to the local network without requiring authentication. An unauthenticated attacker can connect via a TCP socket or send HTTP requests to trigger error responses that reveal device headers and build versions.
Business impact
The ability for unauthenticated actors to interact with internal device services poses a severe risk to organizational security, potentially facilitating further lateral movement or information gathering. With a CVSS score of 7.5, this high-severity vulnerability could lead to unauthorized system exposure, undermining the integrity and confidentiality of the payment infrastructure.
Remediation
Immediate Action: Restrict network access to port 8888 on all affected Dataphone A920 devices via firewall rules to ensure the service is not reachable by unauthorized parties.
Proactive Monitoring: Monitor network traffic for unauthorized TCP connections or anomalous HTTP requests directed at port 8888 on internal payment devices.
Compensating Controls: Implement strict network segmentation or VLAN isolation to ensure that the Dataphone A920 device is not accessible from untrusted segments of the corporate network.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub repository.
Analyst recommendation
Given the exposure of internal device functionality to the network, administrators must treat this vulnerability with high urgency. Please isolate the affected devices from any untrusted network segments immediately and monitor for unauthorized access attempts until a vendor-supplied security patch is officially released and applied.