Executive brief
PAX Technology Q80 is a payment terminal used in retail and hospitality environments. This vulnerability in the AIP file installer allows a network-adjacent attacker to write arbitrary files and execute code with root privileges, potentially compromising point-of-sale operations, customer payment data, and system integrity. No authentication is required to exploit this flaw.
Technical details
This is a symlink-following (TOCTOU) vulnerability in the AIP file parsing logic of the PAX Q80 installer. An attacker on the adjacent network can craft a malicious AIP file containing symbolic links that, when processed during installation, allows arbitrary file write. By combining this with additional vulnerabilities, an attacker can achieve remote code execution in the context of root. The attack vector is network-adjacent (not network-wide), requires the installer process to be active, and does not require authentication. The vendor initially claimed the affected firmware was end-of-life and unsupported, but later confirmed the issue affects the reported build and disputed impact on newer releases.
Affected products
- PAX Technology Q80 <UNKNOWN>
Timeline
- 2026-04-22: disclosed: Vulnerability reported to vendor
- 2026-08-05: advisory: ZDI coordinated public release of advisory ZDI-26-525
- 2026-08-14: other: Advisory published