CVE-2026-19910

7.5

PAX Technology · Q80

A signature verification bypass vulnerability exists in the PAX Technology Q80 application installer, which could allow an attacker to execute arbitrary code.

Executive summary

A critical remote code execution vulnerability in the PAX Technology Q80 application installer poses a significant risk to device integrity and security.

Vulnerability

This vulnerability, identified as CWE-347, stems from the improper verification of cryptographic signatures during the application installation process. The attack vector is adjacent, and successful exploitation does not require user interaction or authentication.

Business impact

Successful exploitation of this flaw allows an attacker to bypass security controls and execute arbitrary code on the affected PAX Q80 device. Given the CVSS score of 7.5, this high severity vulnerability could result in full system compromise, unauthorized data access, and the potential for persistent malware installation on payment terminals.

Remediation

Immediate Action: Organizations should restrict network access to affected terminals and monitor vendor channels for the release of an official security patch.

Proactive Monitoring: Security teams should monitor device logs for unusual installation activity or unauthorized process executions originating from the application installer.

Compensating Controls: Implement strict network segmentation to ensure that only authorized management systems can communicate with the Q80 devices, effectively limiting the adjacent attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention to network security and access control. Administrators must prioritize the installation of vendor-provided patches as soon as they become available to eliminate the underlying signature verification flaw.

More PAX Technology CVEs