Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.
The following versions of PayRange API are affected:
The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
PayRange API
MitigationPayRange has not responded to requests to work with CISA to mitigate this vulnerability. Users of PayRange devices are invited to co...