← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 12:00via CISA Alerts

PayRange API

Brief

View CSAF

Summary

Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image. The following versions of PayRange API are affected: PayRange API vers:all/* CVSS Vendor Equipment Vulnerabilities

v3 8.8 PayRange PayRange API Missing Authorization

Background

Critical Infrastructure Sectors: Commercial Facilities

Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18965 The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.

Read more on CISA Alerts