CRITICAL🇵🇱 Wersja polska

CVE-2026-8076

CVSS 9.3v4.0pub. 2026-05-08

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed since 2012. This could allow an attacker to easily perform a brute-force attack against a user and gain access by trying different PINs without the account being locked. Successful exploitation of this vulnerability could result in unauthorized access to confidential configuration settings, compromising the security of the system.

🤖 AI Analysis
How it works

The CashDro 3 system supports authentication based on numeric PINs, retained for compatibility with POS software integrated since 2012. The absence of an account lockout mechanism after a specified number of failed login attempts allows an attacker to systematically check consecutive PIN combinations without any restrictions. As a result, a remote attacker, without authentication and without user interaction, can use a brute-force method to guess the correct PIN and log in to the admin panel.

Impact

Successful exploitation of this vulnerability allows an attacker to obtain unauthorized access to sensitive configuration settings of the CashDro 3 system, compromising the security of the entire device. Given that the system is used in point-of-sale (POS) environments, access to the admin panel can have serious financial and operational consequences.

Mitigation & patch

Apply patches available from the vendor according to the references provided. Additionally, it is recommended to implement an account lockout policy after a specified number of failed login attempts, enforce stronger authentication methods instead of numeric PINs, and restrict access to the admin panel exclusively to trusted IP addresses or internal networks.

Who is affected

CashDro 3 version 24.01.00.26 — a cash register/POS system with a web admin panel

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References