VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities

2026-07-09T20:52:10Z09dbb40894a5b42474747f2d4ed54562e924c89fce428fa272ee2859c1a04e69
API over‑fetchingAdaloAndroidCORSJWT exposureJavaScript injectionPayRangeRCESSL/TLS bypassStripeTendaWebViewXSSXerte Online Toolkitantivirus binary pathauthentication bypassauthorization failurecredential theftdata exposurefirmware backdoorhardware controlno-code platformremote code executionsetup directory persistenceundocumented backdoor authentication

What happened

This document aggregates multiple vulnerability advisories affecting a range of products: PayRange Android app (WebView SSL bypass and JavaScript injection enabling credential theft and hardware control), Xerte Online Toolkit (post-installation setup persistence allowing reconfiguration/auth bypass and an editable antivirus path enabling RCE), Adalo platform (platform-level API over‑fetching and exposed long‑lived JWTs leading to mass user‑data disclosure), multiple Tenda firmware images (undocumented backdoor granting admin access), HP Deskjet 2800 series firmware (missing authorization onAPI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
09dbb40894a5b42474747f2d4ed54562e924c89fce428fa272ee2859c1a04e69
Enrichment time
2026-07-09T20:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.