CVE-2026-4582 PUBLISHED

Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authentication

Assigner: VulDB
Reserved: 22.03.2026 Published: 23.03.2026 Updated: 23.03.2026

A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the local network. Attacks of this nature are highly complex. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 2.3

Product Status

Vendor Shenzhen HCC Technology
Product MPOS M6 PLUS
Versions
  • Version 1V.31-N is affected

Credits

  • davimo (VulDB User) reporter
  • VulDB coordinator

References

Problem Types

  • Missing Authentication CWE
  • Improper Authentication CWE