CVE-2026-4584 PUBLISHED

Shenzhen HCC Technology MPOS M6 PLUS Cardholder Data cleartext transmission

Assigner: VulDB
Reserved: 22.03.2026 Published: 23.03.2026 Updated: 23.03.2026

A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information. The attack requires access to the local network. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 2.3

Product Status

Vendor Shenzhen HCC Technology
Product MPOS M6 PLUS
Versions
  • Version 1V.31-N is affected

Credits

  • davimo (VulDB User) reporter
  • VulDB coordinator

References

Problem Types

  • Cleartext Transmission of Sensitive Information CWE
  • Cryptographic Issues CWE