PayRange API
Plan PatchCVSS 8.8ICS-CERT ICSA-26-237-04Aug 25, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
PayRange API allows successful exploitation to disclose sensitive information, arbitrarily modify the device to cause denial of service, or alter a device's displayed image. The vulnerability affects all versions of the PayRange API.
What this means
What could happen
An attacker with network access could read sensitive data from PayRange payment terminals, disable them, or alter what they display to customers—disrupting payment processing and potentially tampering with transaction information.
Who's at risk
Water authorities and utilities operating PayRange payment kiosks for customer bill payment should be concerned. This affects any PayRange-enabled payment terminals used for accepting utility payments or other customer transactions.
How it could be exploited
An authenticated or unauthenticated attacker on the network can reach the PayRange API endpoint and exploit improper authorization controls (CWE-862) to read, modify, or disrupt device functionality without appropriate permission checks.
Prerequisites
- Network access to PayRange API endpoint
- May require valid credentials depending on attack vector
remotely exploitableno patch availableimproper authorization (CWE-862)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
PayRange APIAll versionsNo fix yet
Remediation & Mitigation
0/3
Do now
0/2WORKAROUNDContact PayRange customer support at support@payrange.com immediately to request security guidance and available mitigations
HARDENINGRestrict network access to PayRange API endpoints to authorized payment terminals and systems only; implement firewall rules to limit connections
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HARDENINGMonitor PayRange devices for unexpected changes to displayed content, configuration, or availability
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/da37465c-9883-42d4-9723-85fd84299a8aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.