Junglewise Threat Intelligence

CVE-2025-4130: PAVO Inc. PAVO Pay hard-coded credentials

CVE-2025-4130 · Severity: high · CVSS 7.5 · Published 2025-07-21

Technologies: PAVO Inc. Pay. Vendors: PAVO Inc..

Executive brief

PAVO Pay, a payment processing solution, contains a security flaw where sensitive credentials or cryptographic keys are permanently embedded within its software code. An unauthorized person could extract these secrets to gain access to restricted data or systems. This could lead to the exposure of sensitive financial information or unauthorized access to the payment platform.

Technical details

A Use of Hard-coded Credentials vulnerability (CWE-798) exists in PAVO Pay versions prior to 13.05.2025. The application contains sensitive constants, such as passwords or cryptographic keys, embedded directly within the executable file. A remote, unauthenticated attacker can exploit this by reading the executable to retrieve these sensitive constants. This can lead to a complete loss of confidentiality for the affected secrets, potentially enabling further unauthorized access to the system or its data. Users are advised to update to the version released on or after May 13, 2025.

Affected products

  • PAVO Inc. PAVO Pay before 13.05.2025

Timeline

  • 2025-07-21: advisory: Initial publication of the CVE record.
  • 2025-05-13: patched: The vulnerability is addressed in versions released on or after this date.

References

Related threats