目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-46018 PoC — Opay Mobile application 安全漏洞

来源
关联漏洞
标题: Opay Mobile application 安全漏洞 (CVE-2025-46018)
Description:Opay Mobile application是Opay公司的一个轻量级应用程序。用于管理所有银行或支付需求。 Opay Mobile application 2.19.4版本存在安全漏洞,该漏洞源于允许用户在交易特定时刻通过禁用蓝牙绕过支付授权,可能导致未经授权使用洗衣服务和财务损失。
Description
Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"
介绍
# CVE-2025-46018 – CSC Pay Mobile App Payment Authentication Bypass

## Summary

A **payment authentication bypass vulnerability** was discovered in the CSC Pay Mobile App, affecting version **2.19.4**. The flaw allowed an attacker to initiate a payment, disable Bluetooth at a specific point in the process, and activate a laundry machine **without being charged**.

This issue has been responsibly disclosed and is now tracked as **CVE-2025-46018**.

---

## Affected Product

- **Product**: CSC Pay Mobile App  
- **Version**: 2.19.4 (fixed in version 2.20.0)  
- **Component**: Bluetooth payment authentication module  
- **Vendor**: CSC ServiceWorks

---

## Vulnerability Type

- CWE-284: Improper Access Control  
- CVSS (estimated): Medium severity  
- Exploit type: Local – requires proximity to the machine

---

## Attack Vector (High-Level)

1. The attacker initiates a payment via the mobile app and scans the QR code on a laundry machine.
2. Before the app completes Bluetooth authentication and charges the user, Bluetooth is intentionally disabled.
3. The machine starts the cycle despite no transaction being completed.

**Impact**: Unauthorized use of machines without payment, potential revenue loss, and abuse in public/shared environments.

---

## Timeline

| Date            | Event                                      |
|-----------------|--------------------------------------------|
| April 13, 2025  | Vulnerability discovered                   |
| April 16, 2025  | Reported to CSC ServiceWorks               |
| June 4, 2025    | CVE-2025-46018 assigned by MITRE           |
| July 2025       | Vendor acknowledged issue fixed            |
| Version 2.20.0  | Issue resolved in app update               |

---

## Acknowledgment

**Discoverer**: Niranjan Gaire  
- [CSC ServiceWorks Security Hall of Fame](https://www.cscsw.com/disclosure-process/)  
- [MITRE CVE Record – CVE-2025-46018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46018) 

---

## Disclaimer

This repository is for documentation and responsible disclosure purposes only.  
**No exploit code or reproduction steps will be shared publicly.**

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →