IM
IronMonkey Threat Research
‹ Back to ICS Advisories

PayRange API

HIGH
CVSS 8.8
Date 2026-08-25T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-18965 8.8 high
The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.

// Remediations (1)

Mitigation: PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of Pa
PayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to contact PayRange customer support at [email protected] for additional information.

// References