Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-46018 PoC — Opay Mobile application 安全漏洞

Source
Associated Vulnerability
Title: Opay Mobile application 安全漏洞 (CVE-2025-46018)
Description:CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.
Description
Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"
Readme
# CVE-2025-46018 – CSC Pay Mobile App Payment Authentication Bypass

## Summary

A **payment authentication bypass vulnerability** was discovered in the CSC Pay Mobile App, affecting version **2.19.4**. The flaw allowed an attacker to initiate a payment, disable Bluetooth at a specific point in the process, and activate a laundry machine **without being charged**.

This issue has been responsibly disclosed and is now tracked as **CVE-2025-46018**.

---

## Affected Product

- **Product**: CSC Pay Mobile App  
- **Version**: 2.19.4 (fixed in version 2.20.0)  
- **Component**: Bluetooth payment authentication module  
- **Vendor**: CSC ServiceWorks

---

## Vulnerability Type

- CWE-284: Improper Access Control  
- CVSS (estimated): Medium severity  
- Exploit type: Local – requires proximity to the machine

---

## Attack Vector (High-Level)

1. The attacker initiates a payment via the mobile app and scans the QR code on a laundry machine.
2. Before the app completes Bluetooth authentication and charges the user, Bluetooth is intentionally disabled.
3. The machine starts the cycle despite no transaction being completed.

**Impact**: Unauthorized use of machines without payment, potential revenue loss, and abuse in public/shared environments.

---

## Timeline

| Date            | Event                                      |
|-----------------|--------------------------------------------|
| April 13, 2025  | Vulnerability discovered                   |
| April 16, 2025  | Reported to CSC ServiceWorks               |
| June 4, 2025    | CVE-2025-46018 assigned by MITRE           |
| July 2025       | Vendor acknowledged issue fixed            |
| Version 2.20.0  | Issue resolved in app update               |

---

## Acknowledgment

**Discoverer**: Niranjan Gaire  
- [CSC ServiceWorks Security Hall of Fame](https://www.cscsw.com/disclosure-process/)  
- [MITRE CVE Record – CVE-2025-46018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46018) 

---

## Disclaimer

This repository is for documentation and responsible disclosure purposes only.  
**No exploit code or reproduction steps will be shared publicly.**

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →