HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Signature Verification Bypass Enables Remote Code Execution in PAX Technology Q80 POS Terminals (ZDI‑26‑526)

A zero‑day flaw in the PAX Q80 installer bypasses signature verification, allowing network‑adjacent attackers to execute code as root. Retail merchants using these POS devices face potential compromise, highlighting the need for strict code‑signing controls and continuous audit evidence.

LiveThreat™ Intelligence · 📅 August 06, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Signature Verification Bypass Enables Remote Code Execution in PAX Technology Q80 POS Terminals (ZDI‑26‑526)

What Happened — A zero‑day vulnerability (CVSS 7.5) in the PAX Technology Q80 application installer bypasses cryptographic signature verification, allowing a network‑adjacent attacker to execute arbitrary code with root privileges. No authentication is required.

Why It Matters for Compliance & Audit Readiness

  • The flaw demonstrates a control gap in code‑signing verification, a core requirement of SOC 2 CC6.1 (System Operations) and CC3.1 (Change Management).
  • Continuous evidence of proper code‑signing controls and configuration baselines is essential to prove that such gaps are identified and mitigated before an audit.
  • Verifying that all payment‑terminal firmware is signed and that only approved images are installed aligns directly with the Control Mapping capability, providing auditable proof for SOC 2 readiness.

Who Is Affected — Retail and hospitality merchants that deploy PAX Q80 point‑of‑sale terminals; payment‑service providers that integrate these devices.

Recommended Actions

  • Inventory all Q80 devices and confirm they run supported, signed firmware.
  • Enforce network segmentation to isolate POS terminals from adjacent networks.
  • Implement continuous monitoring of firmware signatures and maintain immutable logs as audit evidence.
  • Engage with PAX for a remediation roadmap or consider temporary removal of affected units.

Source: Zero Day Initiative Advisory ZDI‑26‑526

Technical Notes

  • CVSS 7.5 (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
  • Exploits a missing signature verification step in the installer, leading to root‑level RCE.
  • No public exploit code released; vendor initially claimed the firmware was end‑of‑life, later confirmed the issue.

Source: Zero Day Initiative Advisory ZDI‑26‑526

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-526/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →