CVE-2025-61234

7.5

Dataphone · A920

An unauthenticated access control vulnerability in Dataphone A920 v2025.07.161103 exposes a local network service on port 8888, allowing unauthorized interaction and system information disclosure.

Executive summary

An unauthenticated access control flaw in the Dataphone A920 device allows remote attackers to interact with internal services and disclose sensitive system information, presenting a significant security risk.

Vulnerability

This vulnerability involves incorrect access control that exposes a service on port 8888 to the local network without requiring authentication. An unauthenticated attacker can connect via a TCP socket or send HTTP requests to trigger error responses that reveal device headers and build versions.

Business impact

The ability for unauthenticated actors to interact with internal device services poses a severe risk to organizational security, potentially facilitating further lateral movement or information gathering. With a CVSS score of 7.5, this high-severity vulnerability could lead to unauthorized system exposure, undermining the integrity and confidentiality of the payment infrastructure.

Remediation

Immediate Action: Restrict network access to port 8888 on all affected Dataphone A920 devices via firewall rules to ensure the service is not reachable by unauthorized parties.

Proactive Monitoring: Monitor network traffic for unauthorized TCP connections or anomalous HTTP requests directed at port 8888 on internal payment devices.

Compensating Controls: Implement strict network segmentation or VLAN isolation to ensure that the Dataphone A920 device is not accessible from untrusted segments of the corporate network.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub repository.

Analyst recommendation

Given the exposure of internal device functionality to the network, administrators must treat this vulnerability with high urgency. Please isolate the affected devices from any untrusted network segments immediately and monitor for unauthorized access attempts until a vendor-supplied security patch is officially released and applied.

Sources