Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed since 2012. This could allow an attacker to easily perform a brute-force attack against a user and gain access by trying different PINs without the account being locked. Successful exploitation of this vulnerability could result in unauthorized access to confidential configuration settings, compromising the security of the system.
The CashDro 3 system supports authentication based on numeric PINs, retained for compatibility with POS software integrated since 2012. The absence of an account lockout mechanism after a specified number of failed login attempts allows an attacker to systematically check consecutive PIN combinations without any restrictions. As a result, a remote attacker, without authentication and without user interaction, can use a brute-force method to guess the correct PIN and log in to the admin panel.
Successful exploitation of this vulnerability allows an attacker to obtain unauthorized access to sensitive configuration settings of the CashDro 3 system, compromising the security of the entire device. Given that the system is used in point-of-sale (POS) environments, access to the admin panel can have serious financial and operational consequences.
Apply patches available from the vendor according to the references provided. Additionally, it is recommended to implement an account lockout policy after a specified number of failed login attempts, enforce stronger authentication methods instead of numeric PINs, and restrict access to the admin panel exclusively to trusted IP addresses or internal networks.
CashDro 3 version 24.01.00.26 — a cash register/POS system with a web admin panel
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X