CyberRota Analysis
AI-GeneratedThe PayRange API lacks proper authorization on its management endpoints, exposing detailed information about all devices on the PayRange network to unauthorized users, regardless of account status. This vulnerability poses a significant risk as it could lead to data leakage and potential exploitation of the devices. Organizations utilizing PayRange services should prioritize addressing this issue to safeguard their network integrity and protect sensitive device information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PayRange APIĀ is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.