PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command.
The attacker must have physical USB access to the device in order to exploit this vulnerability.
Conclusion & alert: CVE-2023-42134 is rated Exploit Available (57.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.56%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2023-42134
Exploit prediction scoring system (EPSS) score for CVE-2023-42134
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).