PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition.





The attacker must have physical USB access to the device in order to exploit this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-46594 PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. The attacker must have physical USB access to the device in order to exploit this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-06-17T21:09:22.557Z

Reserved: 2023-09-07T13:17:57.372Z

Link: CVE-2023-42135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-01-15T14:15:24.413

Modified: 2024-11-21T08:22:20.747

Link: CVE-2023-42135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.