Impact
A missing authentication flaw in the FitSoft POS System permits unauthenticated remote attackers to directly log in and control the entire point‑of‑sale interface, potentially altering transaction records, exposing sensitive customer data, and disrupting business operations. The vulnerability is identified as CWE‑306, which allows an attacker to bypass any login requirement.
Affected Systems
The vulnerability affects the FitSoft POS System. No specific version information is provided, so all installations of this product are considered potentially impacted until a vendor‑issued remedy is applied.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity, indicating significant potential damage to confidentiality, integrity, and availability. While the vulnerability is not yet listed in the CISA KEV catalog and no exploitation probability has been published, the lack of authentication still poses a critical risk. The attacker can remotely reach the POS system’s management interface from any network‑connected device, allowing direct control over the point‑of‑sale operations.
OpenCVE Enrichment