Ad

CVE-2026-4584

LOW CVSS 4.0: 2.3 EPSS 0.01%
Updated Mar 23, 2026
Shenzhen
Parameter Value
CVSS 2.3 (LOW)
Type CWE-319 (Cleartext Transmission), CWE-310 (Cryptographic Issues)
Vendor Shenzhen
Public PoC Yes

A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information.

The attack requires access to the local network. The attack requires a high level of complexity. It is indicated that the exploitability is difficult.

The vendor was contacted early about this disclosure but did not respond in any way.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
High
Difficult to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0