ZeroHour

CVE-2026-19910

large

Signature Verification Bypass RCE in PAX Technology Q80 Application Installer

CVSS 3.0
7.5 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-19910 (tracked as ZDI-CAN-30585, disclosed as ZDI-26-526) is an improper cryptographic signature verification flaw (CWE-347) in the application installer of PAX Technology Q80 payment terminals. A network-adjacent, unauthenticated attacker can supply an application package that the installer accepts without verifying its cryptographic signature, allowing malicious applications to be installed on the device. Successful exploitation yields arbitrary code execution, and when combined with other vulnerabilities the attacker can run code in the context of root. Any deployed Q80 terminal reachable from an adjacent network segment, such as a store LAN or Wi-Fi, is affected; no affected or fixed version ranges were specified in the available data. No public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS currently estimates only a 0.2% probability of exploitation within 30 days.

What to do: Monitor the PAX advisory and ZDI-26-526 for the fixed firmware release and update Q80 terminals promptly once a patched version is published, since no fixed version is named in the available data. Until then, segment terminals away from untrusted adjacent networks (e.g., a dedicated VLAN separate from guest or customer Wi-Fi), restrict application installation and updates to trusted management channels such as the vendor's device management platform, and avoid sideloading application packages directly onto devices. With no known public PoC and low EPSS, patching in a normal maintenance window is reasonable, but merchants with flat in-store networks should prioritize segmentation.

Affected
PAX Technology Q80 (application installer component)
Estimated exposure
largeplausibly on the order of 100,000+ deployed Q80 terminals worldwide (exact Q80 install base not published) — PAX is one of the largest global payment terminal vendors by shipment volume, with tens of millions of cumulative terminals in the field and the Q80 among its Android smart terminal models, but no public Q80-specific install counts exist,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the application installer. The issue results from the lack of proper verification of a cryptographic signature before installing an application. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-30585.

Weakness
CWE-347
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

ZDI discloses an unauthenticated, network-adjacent RCE in PAX Technology Q80 payment terminals via installer signature bypass, rated CVSS 7.5.

ZDI-26-526 describes a signature verification bypass in the PAX Technology Q80 application installer that lets network-adjacent attackers execute arbitrary code without authentication. The 0-day is tracked as CVE-2026-19910 and CVE-2026-19911 and carries a CVSS score of 7.5. No public patch was noted at the time of disclosure.